IOC Report
setup.msi

loading gif

Files

File Path
Type
Category
Malicious
setup.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {394343F4-E39C-409D-BD57-1C70A6E4B89C}, Number of Words: 10, Subject: Cave App, Author: Weqos Apps Industries, Name of Creating Application: Cave App, Template: x64;2057, Comments: This installer database contains the logic and data required to install Cave App., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Thu Dec 26 06:52:15 2024, Last Saved Time/Date: Thu Dec 26 06:52:15 2024, Last Printed: Thu Dec 26 06:52:15 2024, Number of Pages: 450
initial sample
malicious
C:\Users\user\AppData\Local\Temp\msi9DD9.txt
Unicode text, UTF-16, little-endian text, with no line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\pss9DEC.ps1
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\scr9DDA.ps1
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\Config.Msi\4b7479.rbs
data
modified
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_5013smuh.krx.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_rs3tdj25.ryl.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\Installer\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}\icon_22.exe
MS Windows icon resource - 7 icons, 256x256, 32 bits/pixel, -128x-128, 32 bits/pixel
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\BCUninstaller.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\ImporterREDServer.exe
PE32+ executable (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\UnRar.exe
PE32+ executable (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-console-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-console-l1-2-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-datetime-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-debug-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-errorhandling-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-file-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-file-l1-2-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-file-l2-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-handle-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-heap-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-interlocked-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-libraryloader-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-localization-l1-2-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-memory-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-namedpipe-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-processenvironment-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-processthreads-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-processthreads-l1-1-1.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-profile-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-rtlsupport-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-string-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-synch-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-synch-l1-2-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-sysinfo-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-timezone-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-core-util-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-crt-conio-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-crt-convert-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-crt-environment-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\api-ms-win-crt-filesystem-l1-1-0.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\boost_date_time.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\boost_filesystem.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\boost_program_options.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\boost_regex.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\boost_system.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\boost_threads.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\createdump.exe
PE32+ executable (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\dvacore.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\dvaunittesting.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\ghiuoqfj.rar
RAR archive data, v5
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\msvcp140.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\suriqk.bat
DOS batch file, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\una_front\classes.jsa
data
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\una_front\classes_nocoops.jsa
data
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\una_front\java.datatransfer.jmod
Java jmod module version 1.0
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\una_front\java.desktop.jmod
Java jmod module version 1.0
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\una_front\java.instrument.jmod
Java jmod module version 1.0
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\una_front\java.logging.jmod
Java jmod module version 1.0
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\una_front\java.management.jmod
Java jmod module version 1.0
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\utest.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\vcruntime140.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\vcruntime140_1.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Windows\Installer\4b7477.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {394343F4-E39C-409D-BD57-1C70A6E4B89C}, Number of Words: 10, Subject: Cave App, Author: Weqos Apps Industries, Name of Creating Application: Cave App, Template: x64;2057, Comments: This installer database contains the logic and data required to install Cave App., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Thu Dec 26 06:52:15 2024, Last Saved Time/Date: Thu Dec 26 06:52:15 2024, Last Printed: Thu Dec 26 06:52:15 2024, Number of Pages: 450
dropped
C:\Windows\Installer\4b747a.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {394343F4-E39C-409D-BD57-1C70A6E4B89C}, Number of Words: 10, Subject: Cave App, Author: Weqos Apps Industries, Name of Creating Application: Cave App, Template: x64;2057, Comments: This installer database contains the logic and data required to install Cave App., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Thu Dec 26 06:52:15 2024, Last Saved Time/Date: Thu Dec 26 06:52:15 2024, Last Printed: Thu Dec 26 06:52:15 2024, Number of Pages: 450
dropped
C:\Windows\Installer\MSI7E0C.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI7EAA.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI7EF9.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI7F38.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI7F87.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI7FB7.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI7FE7.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI91AB.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI9D35.tmp
data
dropped
C:\Windows\Installer\MSI9D55.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\SourceHash{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Installer\inprogressinstallinfo.ipi
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Windows\Temp\~DF20789192B87FE5EA.TMP
data
dropped
C:\Windows\Temp\~DF4F72B20018AB3403.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF60F972449EB3B037.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF63A60EEADB8CB2CC.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF70694895213BFD22.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF7E1BBCBCE0E6045E.TMP
data
dropped
C:\Windows\Temp\~DF871E9AC2226C96F6.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFBD59981DEEFEF5C4.TMP
data
dropped
C:\Windows\Temp\~DFC7945C3355FE1489.TMP
data
dropped
C:\Windows\Temp\~DFD2F49BF3F7DCE833.TMP
data
dropped
C:\Windows\Temp\~DFE4C941452133DE67.TMP
data
dropped
C:\Windows\Temp\~DFF9D08DE4615C7890.TMP
data
dropped
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped
There are 82 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Windows\System32\msiexec.exe
"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup.msi"
malicious
C:\Windows\System32\msiexec.exe
C:\Windows\system32\msiexec.exe /V
malicious
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\syswow64\MsiExec.exe -Embedding 60CBBC843D56A986EC6B3BCBD65188DC
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
-NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pss9DEC.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msi9DD9.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scr9DDA.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scr9DDB.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\cmd.exe
C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\suriqk.bat" "C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\ImporterREDServer.exe""
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\createdump.exe
"C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\createdump.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\ImporterREDServer.exe
"C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\ImporterREDServer.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
There are 1 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://successroadway.com/updater.php
172.67.134.27
malicious
http://nuget.org/NuGet.exe
unknown
https://successroadway.com/updater.phpx
unknown
http://pesterbdd.com/images/Pester.png
unknown
https://aka.ms/pscore6lB
unknown
http://crl.microsoft
unknown
http://www.apache.org/licenses/LICENSE-2.0.html
unknown
https://go.micro
unknown
https://contoso.com/
unknown
https://nuget.org/nuget.exe
unknown
https://contoso.com/License
unknown
https://contoso.com/Icon
unknown
http://schemas.mick
unknown
http://xml.org/sax/features/external-general-entitieshttp://xml.org/sax/features/external-parameter-
unknown
https://aka.ms/winui2/webview2download/Reload():
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://github.com/Pester/Pester
unknown
There are 7 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
successroadway.com
172.67.134.27
malicious

IPs

IP
Domain
Country
Malicious
172.67.134.27
successroadway.com
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\4b7479.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\4b7479.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\user\AppData\Roaming\Microsoft\Installer\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\E443C93FE38A0674D88A2F672090B5F4
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\187E38CB2ED78A74793CE2C69CCBDA28
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\E7EE285D6BCFBB0488FD8D57166FADAC
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\51125544FAB230246BBFE149506FE373
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\065A82ED1E5E5304C83A443964682A94
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\89B93D30BB7E2604DB2903D746A2C51F
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\3E23C972A00A3154A9B83D89A4146ABF
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\574D5B86D91DF25448D9F526CAAE9C9D
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\14BA7B05AF5C8754DA7B962E06A867B6
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\9B5AF4DE1AB2060489B6AE7B3EA194D6
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\49982E48A3B4BC04FA606F6079F49621
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\C66308C74B87A2543A43E47D5062F642
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\23FCC08CDC982854E8B3DC110D4BA6F0
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\4E53B16B1EB817146BB92E24C39E71F9
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\EE69BDDFD74852B4581B566E26FC368A
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\DE8D80696CE804542B23A42863608F26
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\6D8E6B71400CBD04BBD221D5C7C12CE1
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\9737E2B1877BA2647A4AC547869EDF03
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\65624D8381D30F249B874F58E818676E
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\1D6B9F26743114741949E7CBD0850B50
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\876E9D03A3628184781AD86C940640F7
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\281AF9D8612EF2E47BDAFD353EBB66DB
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\D63B3F7EA8654C24FB42180178BBBF34
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\C04D16F8CDF5F4543AC9A3616BA42840
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\74BFD8668DF9CDF4DAE798C67C0F5E07
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\E84195AD854B9A744A14CCC0101E24CE
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\1DD769335A51CEF409558BD4F1FD0D16
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\A90F39F166BA2EA44BC33F5B99568A56
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\448F614546145E44A8D80DE268772838
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\05FD0BAA4CB2CD9439DCE5CDE594202A
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\314863730BAF8734C8564E85B3A047C8
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\EA86D228823216D438705787F640D3A5
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\6B5745FE5D94C414FA11D00F7E2AB400
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\6B581FFC20289EB4099D141CDE7359BB
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\99506DC9F6A09D640842631E2BC2AC70
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\210EE68B5FD50E34281311DD8E8CA8CE
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\BF72C907D7DD14443B547200FB74B315
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\E7F5D6A9A9F5C584282653FB24AE4CCB
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\B218C6F033F3D9F4E9F7F1687CFC5E4E
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\ECEF6DC4638DFEF4686CB4AA8C90A457
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\799575847269DFB4B90DB80E9AE3F513
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\9AB49572650F2254CB98AFD3B7DA9B2E
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\1DA51AE393E3A2E44AD642274DF874C9
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\EE9277BB1523DD045952C0B8CCCF2CF8
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\27B23E0DE8354FA4984FE3E6EA64A0DA
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\E053C72B9492790418B6BC8963A132B1
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\418D33948A06A3141BB101F3E34641AE
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\30E3084F57A08354080B6375A86D0459
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\57D46BCA90CDE574793A997F4D70B5FE
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\BE3F70CAE98AB094E896B57BD601796E
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\E571FA2CC5C29C246B485717ABC8D733
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Components\6518C1A5576E11E4FBC0C0E45F2E3C59
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\user\AppData\Roaming\Weqos Apps Industries\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\user\AppData\Roaming\Weqos Apps Industries\Cave App\una_front\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\user\AppData\Roaming\Microsoft\Installer\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}\
HKEY_CURRENT_USER\SOFTWARE\Weqos Apps Industries\Cave App
Version
HKEY_CURRENT_USER\SOFTWARE\Weqos Apps Industries\Cave App
Path
HKEY_CURRENT_USER\SOFTWARE\Weqos Apps Industries\Cave App
TruaiLicQuota
HKEY_CURRENT_USER\SOFTWARE\Weqos Apps Industries\Cave App\Durox
Ver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
LocalPackage
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
AuthorizedCDFPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
Comments
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
Contact
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
HelpLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
HelpTelephone
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
InstallSource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
ModifyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
NoModify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
NoRepair
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
Readme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
URLInfoAbout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
URLUpdateInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
VersionMajor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
VersionMinor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
AuthorizedCDFPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
Comments
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
Contact
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
HelpLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
HelpTelephone
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
InstallSource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
ModifyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
NoModify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
NoRepair
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
Readme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
URLInfoAbout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
URLUpdateInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
VersionMajor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
VersionMinor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\424F5E0DD9224C14E9B1EC66DE7BC6E3
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\InstallProperties
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C4A5FBA-760B-4754-A971-45D0AA1EA01D}
DisplayName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Features\ABF5A4C1B06745749A17540DAAE10AD1
MainFeature
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\Features
MainFeature
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2246122658-3693405117-2476756634-1002\Products\ABF5A4C1B06745749A17540DAAE10AD1\Patches
AllPatches
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
ProductName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
PackageCode
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
Language
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
Version
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
Assignment
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
AdvertiseFlags
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
ProductIcon
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
InstanceType
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
AuthorizedLUAApp
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
DeploymentFlags
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\UpgradeCodes\424F5E0DD9224C14E9B1EC66DE7BC6E3
ABF5A4C1B06745749A17540DAAE10AD1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1\SourceList
PackageName
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1\SourceList\Net
1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1\SourceList\Media
DiskPrompt
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1\SourceList\Media
1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1
Clients
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\ABF5A4C1B06745749A17540DAAE10AD1\SourceList
LastUsedSource
There are 129 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2AD0000
trusted library allocation
page read and write
6A7E000
stack
page read and write
5999000
trusted library allocation
page read and write
70F0000
trusted library allocation
page read and write
7FFE1A520000
unkown
page readonly
7087000
heap
page read and write
2B15000
trusted library allocation
page execute and read and write
7330000
trusted library allocation
page read and write
190000
heap
page read and write
7061000
heap
page read and write
5031000
trusted library allocation
page read and write
7028000
heap
page read and write
7340000
trusted library allocation
page read and write
140000000
unkown
page readonly
2B30000
trusted library allocation
page read and write
2879000
heap
page read and write
23C89020000
heap
page read and write
2932000
heap
page read and write
7120000
trusted library allocation
page read and write
7E0D000
stack
page read and write
2AA0000
heap
page read and write
4AC6000
trusted library allocation
page read and write
7FF7C849D000
unkown
page readonly
7D80000
trusted library allocation
page read and write
2B12000
trusted library allocation
page read and write
7FF7C8498000
unkown
page readonly
7097000
heap
page read and write
25BD000
stack
page read and write
7FFE1A521000
unkown
page execute read
140001000
unkown
page execute read
1B0000
heap
page read and write
23C890C0000
heap
page read and write
2B70000
trusted library allocation
page read and write
2B10000
trusted library allocation
page read and write
2980000
heap
page read and write
140013000
unkown
page readonly
57D000
heap
page read and write
48AE000
stack
page read and write
4971000
trusted library allocation
page read and write
180479000
unkown
page readonly
180426000
unkown
page write copy
14C000
stack
page read and write
140000000
unkown
page readonly
7FFE1A529000
unkown
page readonly
570000
heap
page read and write
72E0000
trusted library allocation
page read and write
72A0000
trusted library allocation
page read and write
7280000
trusted library allocation
page read and write
7FF7C8491000
unkown
page execute read
2B88000
heap
page read and write
7D70000
heap
page read and write
7170000
heap
page execute and read and write
2AE0000
trusted library allocation
page read and write
706D000
heap
page read and write
28CD000
heap
page read and write
8E8FD7D000
stack
page read and write
7119000
trusted library allocation
page read and write
71FF000
stack
page read and write
140013000
unkown
page readonly
6CBB000
stack
page read and write
48B5000
heap
page execute and read and write
1802BD000
unkown
page readonly
48FE000
stack
page read and write
4C1E000
trusted library allocation
page read and write
7FFE1A546000
unkown
page read and write
6A3B000
stack
page read and write
7FFE1A525000
unkown
page readonly
2AF0000
trusted library allocation
page read and write
43B0000
trusted library allocation
page read and write
4F9E000
trusted library allocation
page read and write
14001A000
unkown
page read and write
723E000
stack
page read and write
14001B000
unkown
page readonly
23C89040000
heap
page read and write
436E000
stack
page read and write
14001A000
unkown
page write copy
7009000
heap
page read and write
7370000
trusted library allocation
page read and write
482E000
stack
page read and write
7FFE01477000
unkown
page readonly
71BE000
stack
page read and write
69FD000
stack
page read and write
7FFE1A547000
unkown
page readonly
24F7000
stack
page read and write
2B80000
heap
page read and write
7E4F000
stack
page read and write
7E70000
trusted library allocation
page read and write
2840000
heap
page read and write
72F0000
trusted library allocation
page read and write
43B8000
trusted library allocation
page read and write
486E000
stack
page read and write
6E3E000
stack
page read and write
7FF7C8491000
unkown
page execute read
7FFE013F1000
unkown
page execute read
2AF9000
trusted library allocation
page read and write
7EB5000
trusted library allocation
page read and write
6D6E000
stack
page read and write
7320000
trusted library allocation
page read and write
180000000
unkown
page readonly
6B40000
heap
page read and write
7FF7C8490000
unkown
page readonly
7067000
heap
page read and write
7310000
trusted library allocation
page read and write
7360000
trusted library allocation
page read and write
7110000
trusted library allocation
page read and write
705B000
heap
page read and write
28F8000
heap
page read and write
6EBE000
stack
page read and write
2AE4000
trusted library allocation
page read and write
4C30000
trusted library allocation
page read and write
4450000
heap
page read and write
29C0000
heap
page read and write
6ABF000
stack
page read and write
48B0000
heap
page execute and read and write
47EE000
stack
page read and write
7FFE1A530000
unkown
page readonly
4960000
heap
page read and write
7FF7C849D000
unkown
page readonly
6B3D000
stack
page read and write
7350000
trusted library allocation
page read and write
6DAB000
stack
page read and write
7EC0000
trusted library allocation
page read and write
8E9007F000
stack
page read and write
180429000
unkown
page write copy
4FDD000
trusted library allocation
page read and write
7390000
trusted library allocation
page execute and read and write
2B50000
trusted library allocation
page execute and read and write
70F7000
trusted library allocation
page read and write
24FD000
stack
page read and write
72C0000
trusted library allocation
page read and write
493E000
stack
page read and write
7E60000
trusted library allocation
page execute and read and write
7FF7C849C000
unkown
page write copy
6C7E000
stack
page read and write
29C6000
heap
page read and write
7FFE01474000
unkown
page write copy
25FE000
stack
page read and write
7DC0000
trusted library allocation
page read and write
297E000
stack
page read and write
519C000
trusted library allocation
page read and write
23C89060000
heap
page read and write
440C000
stack
page read and write
6FF0000
heap
page read and write
2AED000
trusted library allocation
page execute and read and write
24BC000
stack
page read and write
707A000
heap
page read and write
72D0000
trusted library allocation
page read and write
6E7E000
stack
page read and write
23C890CB000
heap
page read and write
6AFD000
stack
page read and write
180001000
unkown
page execute read
140001000
unkown
page execute read
59D9000
trusted library allocation
page read and write
5979000
trusted library allocation
page read and write
2B40000
heap
page readonly
5971000
trusted library allocation
page read and write
7E50000
heap
page read and write
86E000
stack
page read and write
7100000
trusted library allocation
page read and write
76E000
stack
page read and write
727D000
stack
page read and write
7FFE013F0000
unkown
page readonly
7FF7C849C000
unkown
page read and write
8E8FEFF000
stack
page read and write
4C2E000
trusted library allocation
page read and write
7380000
trusted library allocation
page read and write
7FFE1A541000
unkown
page readonly
1802BB000
unkown
page read and write
7300000
trusted library allocation
page read and write
49CB000
trusted library allocation
page read and write
444E000
stack
page read and write
579000
heap
page read and write
7048000
heap
page read and write
72B0000
trusted library allocation
page execute and read and write
7FF7C8498000
unkown
page readonly
2B60000
heap
page execute and read and write
14001B000
unkown
page readonly
23C89010000
heap
page read and write
43AF000
stack
page read and write
2848000
heap
page read and write
4C2A000
trusted library allocation
page read and write
7FFE01473000
unkown
page read and write
7055000
heap
page read and write
7287000
trusted library allocation
page read and write
2AE3000
trusted library allocation
page execute and read and write
6EF2000
heap
page read and write
7FFE1A531000
unkown
page execute read
180428000
unkown
page read and write
283E000
stack
page read and write
286D000
heap
page read and write
2570000
heap
page read and write
4D39000
trusted library allocation
page read and write
6DFE000
stack
page read and write
7D90000
heap
page read and write
7FFE01445000
unkown
page readonly
7FF7C8490000
unkown
page readonly
7FFE1A528000
unkown
page read and write
There are 187 hidden memdumps, click here to show them.