Summary | ZeroBOX

InstallSetup1.exe

Gen1 Generic Malware NSIS Malicious Library Malicious Packer Admin Tool (Sysinternals etc ...) Antivirus UPX Anti_VM PNG Format OS Processor Check MZP Format CAB CHM Format dll JPEG Format PE64 PE File DLL DllRegisterServer ZIP Format BMP Format icon PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 13, 2023, 10:36 a.m. Nov. 13, 2023, 10:50 a.m.
Size 2.5MB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 92907b257d087fa3e9fa0a72dc15772e
SHA256 8980cdbe1758699564fbda64e27ef1f03348b60216d4d581aae650839a12ee93
CRC32 F9E39C94
ssdeep 49152:Ch2s5FXQ4EmojLjCRELVf7Avil+dHIsLp1thIikN+6u2hsT:C3zX71oDCRAZUviAHImDqia7hsT
Yara
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • NSIS_Installer - Null Soft Installer
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: c:\$Recycle.bin\S-1-5-~1 -
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The directory is not empty.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: c:\$Recycle.bin\S-1-5-~1\desktop.ini -
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: Access is denied.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The directory is not empty.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: The system cannot find the file specified.
console_handle: 0x0000000b
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2172
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x003f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9928007680
free_bytes_available: 9928007680
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9928007680
free_bytes_available: 9928007680
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9932582912
free_bytes_available: 9932582912
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9932582912
free_bytes_available: 9932582912
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9954029568
free_bytes_available: 9954029568
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9954029568
free_bytes_available: 9954029568
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9954029568
free_bytes_available: 9954029568
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9954029568
free_bytes_available: 9954029568
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10065657856
free_bytes_available: 10065657856
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10065649664
free_bytes_available: 10065649664
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10065649664
free_bytes_available: 10065649664
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10065649664
free_bytes_available: 10065649664
root_path: C:
total_number_of_bytes: 34252779520
1 1 0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cache\index
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
file C:\Users\test22\AppData\Roaming\Opera\Opera\global_history.dat
file C:\Users\test22\AppData\Local\Temp\Broom.exe
file C:\Users\test22\AppData\Local\Temp\SandboxieInstall.exe
file C:\Users\test22\AppData\Local\Temp\202005191702_6d173b9549ce4fe1e5ada5ab9ce0bfff5d9569f19e7fa916db5c8d4f0dace63b_setup_nwc275a_demo.exe
file C:\Users\test22\AppData\Local\Temp\Setup00000994\OSETUPUI.DLL
file C:\Users\test22\AppData\Local\Temp\Broom.exe
file C:\Users\test22\AppData\Local\Temp\Setup00000994\OSETUP.DLL
file C:\Users\test22\AppData\Local\Temp\Setup000023ac\OSETUP.DLL
file C:\Users\test22\AppData\Local\Temp\Setup000023ac\ose00000.exe
file C:\Users\test22\AppData\Local\Temp\Setup00000994\ose00000.exe
file C:\Users\test22\AppData\Local\Temp\InstallSetup1.exe
file C:\Users\test22\AppData\Local\Temp\Setup000023ac\OSETUPUI.DLL
file C:\Users\test22\AppData\Local\Temp\SandboxieInstall.exe
file c:\$RECYCLE.BIN\S-1-5-21-3832866432-4053218753-3017428901-1001\desktop.ini
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_207_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_9e455618fbfe7d2cd7c8c778da6201af_31bf3856ad364e35_6.1.7601.22923_none_71e47a370a53121e.manifest
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_159_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_18_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.mum
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_164_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_7_for_kb3075220_bf~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_6.1.7601.18717_da-dk_12122c0f7fc4f0a3.manifest
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_89_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_124_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_86_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.mum
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_7df1f248c0b27a863791c32500f164b2_31bf3856ad364e35_6.1.7601.22923_none_d5c5c8d711e28aa3.manifest
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_46_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_118_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\x86_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_6.1.7601.23121_he-il_5ce72a74d75126bb.manifest
file C:\Users\test22\AppData\Local\Temp\dd_vcredist_amd64_20180201144548_000_vcRuntimeMinimum_x64.log
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_86_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_microsoft-windows-e..vironment-os-loader_31bf3856ad364e35_6.1.7601.22923_none_9e924fd09a5d7b2f.manifest
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\x86_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_6.1.7601.23121_hr-hr_5f03dd54d6049381.manifest
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_239_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.mum
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_microsoft-windows-ocspsvc.resources_31bf3856ad364e35_6.1.7601.22923_tr-tr_419f57951c930606.manifest
file C:\Windows\SoftwareDistribution\Download\084ae788af8afdcb081a0f76dfc6e551\package_5_for_kb2667402_bf~31bf3856ad364e35~amd64~~6.1.2.0.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_30_for_kb3075220~31bf3856ad364e35~amd64~~6.1.1.0.mum
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22923_el-gr_d4e1d28e140170f7.manifest
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_54_for_kb3075220~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_64_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_209_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.mum
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\amd64_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_6.1.7601.23121_fr-fr_74e61e56a93f9703.manifest
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_219_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\Prefetch\MSCORSVW.EXE-90526FAC.pf
file C:\Users\test22\AppData\Local\Temp\IME2010imeklmg00000026.log
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_85f3170427413796bb9a2006b8b95d44_31bf3856ad364e35_6.1.7601.22923_none_ada1cc7f2dbe7d7b.manifest
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\x86_microsoft-windows-t..tivexcore.resources_31bf3856ad364e35_6.1.7601.23121_nl-nl_2f50a14e86f119cd.manifest
file C:\Windows\Prefetch\RUNDLL32.EXE-5A853E81.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_125_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_216_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_234_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_74_for_kb3075220_bf~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\keys_js5[2].htm
file C:\Windows\Prefetch\RUNDLL32.EXE-4366A668.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_99_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.mum
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_422f6a473f1a2efb618e63ffb7681164_31bf3856ad364e35_6.1.7601.22923_none_8fbdb40163c65432.manifest
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_d914ffe2b0268c4d99b09a381b5f1cbc_31bf3856ad364e35_6.1.7601.18606_none_53d1849499b32cdf.manifest
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_112_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.mum
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_73_for_kb3075220~31bf3856ad364e35~amd64~~6.1.1.0.mum
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_4_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_microsoft-windows-lsa.resources_31bf3856ad364e35_6.1.7601.18606_pl-pl_e422e13f1b5b78a8.manifest
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_209_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_161_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\amd64_microsoft-windows-s..tings-adm.resources_31bf3856ad364e35_6.1.7601.18717_zh-hk_64fb04e3f78a86cd.manifest
file C:\Windows\Prefetch\VBOXDRVINST.EXE-7DCD6070.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_115_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_126_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_122_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\update.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_7_for_kb3075220~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_56_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_69_for_kb3075220_bf~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\Prefetch\PYTHON.EXE-C663CFDC.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_59_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\Prefetch\GOOGLEUPDATESETUP.EXE-305B5E54.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_9_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\Prefetch\AUDIODG.EXE-BDFD3029.pf
file C:\Users\test22\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_201_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_55_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_38_for_kb3075220~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_169_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\Prefetch\THUNDERBIRD.EXE-A0DA674F.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_82_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_159_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\Prefetch\DLLHOST.EXE-4F28A26F.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_113_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_116_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_109_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file c:\Windows\Temp\fwtsqmfile01.sqm
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_53_for_kb3075220~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_27_for_kb3075220~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\Prefetch\SVCHOST.EXE-7AC6742A.pf
file C:\Windows\SoftwareDistribution\Download\0abf0b242f065eda2c392ba806adea85\package_for_kb3010788_sp1~31bf3856ad364e35~amd64~~6.1.1.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_67_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_83_for_kb3075220_bf~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_148_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_205_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\Prefetch\GOOGLEUPDATE.EXE-D0E66F4A.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_163_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_71_for_kb3075220~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\Prefetch\86.0.4240.111_CHROME_INSTALLE-AF26656A.pf
file C:\Windows\Prefetch\CSC.EXE-BE9AC2DF.pf
file c:\Windows\Temp\fwtsqmfile00.sqm
file C:\Windows\SoftwareDistribution\Download\07eadaf7fd5f649833d1a235d8f068f4\package_29_for_kb3075220~31bf3856ad364e35~amd64~~6.1.1.0.cat
file C:\Windows\Prefetch\TASKHOST.EXE-7238F31D.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_212_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_97_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\084ae788af8afdcb081a0f76dfc6e551\package_1_for_kb2667402_bf~31bf3856ad364e35~amd64~~6.1.2.0.cat
file C:\Windows\Prefetch\RUNDLL32.EXE-DE9673F9.pf
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_217_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Users\test22\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_50_for_kb3004375_bf~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\1349c63efc514911e8e09a63876f31b2\package_124_for_kb3004375~31bf3856ad364e35~amd64~~6.1.3.1.cat
file C:\Windows\SoftwareDistribution\Download\084ae788af8afdcb081a0f76dfc6e551\package_5_for_kb2667402~31bf3856ad364e35~amd64~~6.1.2.0.cat