Technical Information
- '%TEMP%\RarSFX1\setup.exe'
- '%TEMP%\RarSFX0\x86.exe'
- '%TEMP%\RarSFX0\D.exe'
- '<SYSTEM32>\msiexec.exe' -Embedding 5C562481AD2E5EFC5FE1A3C18CABA4CF
- '<SYSTEM32>\msiexec.exe' -Embedding DFA0F31827D957DF349117059624767D M Global\MSI0000
- '<SYSTEM32>\msiexec.exe' /i "%TEMP%\RarSFX1\Dazzle Video Capture DVC100 X86 Driver 1.07.msi" SETUPEXEDIR="%TEMP%\RarSFX1" SETUPEXENAME="setup.exe"
- '<SYSTEM32>\msiexec.exe' /V
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\emScan.sys
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\emVFW.dll
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\emFilter.sys
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\EMVIDEO.INF
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\emWHQL.cat
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\emTwain.ds
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\emDevice.sys
- %WINDIR%\Installer\2d961.msi
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\emUSD.dll
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\emProp.ax
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMVIDEO\emYUV.dll
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMAUDIO_x86_x64\EMAUDIO_x86_x64.INF
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- %WINDIR%\Installer\MSIC.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- %WINDIR%\Installer\MSIB.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMAUDIO_x86_x64\emAudio64.sys
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMAUDIO_x86_x64\emWHQL.cat
- %PROGRAM_FILES%\Pinnacle\Dazzle Video Capture DVC100 X86 Driver 1.07\EMAUDIO_x86_x64\emAudio.sys
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\RestorePointSize
- C:\Config.Msi\2d960.rbs
- %WINDIR%\Installer\MSIE.tmp
- <SYSTEM32>\DRVSTORE\EMAUDIO_x8_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emWHQL.cat
- <SYSTEM32>\DRVSTORE\EMAUDIO_x8_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emAudio.sys
- <SYSTEM32>\DRVSTORE\EMAUDIO_x8_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\EMAUDIO_x86_x64.INF
- %WINDIR%\inf\oem3.PNF
- %WINDIR%\Installer\MSI11.tmp
- <SYSTEM32>\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem4.CAT
- %TEMP%\~DFA3A.tmp
- %WINDIR%\Installer\MSI15.tmp
- %WINDIR%\Installer\{EAFC2D5A-0549-4188-A0F1-059E0CC5347F}\ARPPRODUCTICON.exe
- %WINDIR%\inf\oem4.inf
- %WINDIR%\inf\oem4.PNF
- %WINDIR%\inf\oem3.inf
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emDevice.sys
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emProp.ax
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emScan.sys
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\EMVIDEO.INF
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emWHQL.cat
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emTwain.ds
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emFilter.sys
- <SYSTEM32>\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem3.CAT
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emYUV.dll
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emVFW.dll
- <SYSTEM32>\DRVSTORE\EMVIDEO_DD9F166950477D5BF3A8736C757B2F1DAA40BBF4\emUSD.dll
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
- %TEMP%\2987d.msi
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
- %TEMP%\Cab5.tmp
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
- %TEMP%\~3.tmp
- %TEMP%\RarSFX1\setup.exe
- %TEMP%\RarSFX1\Data1.cab
- %TEMP%\RarSFX1\Dazzle Video Capture DVC100 X86 Driver 1.07.msi
- %TEMP%\RarSFX0\D.exe
- %TEMP%\RarSFX0\x86.exe
- %TEMP%\_is1.tmp
- %TEMP%\{0B4D5E58-434B-46AB-90FB-D131AEB2E4AC}\0x0409.ini
- %TEMP%\_is4.tmp
- %TEMP%\_is2.tmp
- %TEMP%\{0B4D5E58-434B-46AB-90FB-D131AEB2E4AC}\Setup.INI
- %TEMP%\{0B4D5E58-434B-46AB-90FB-D131AEB2E4AC}\_ISMSIDEL.INI
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- %TEMP%\~DFBCEC.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- %WINDIR%\Installer\2d95f.ipi
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\rp.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- %TEMP%\Cab9.tmp
- %WINDIR%\Installer\2d95e.msi
- %TEMP%\Cab7.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- <SYSTEM32>\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem4.CAT
- <SYSTEM32>\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem3.CAT
- %WINDIR%\Installer\MSIB.tmp
- %WINDIR%\Installer\MSI11.tmp
- %WINDIR%\Installer\MSIE.tmp
- C:\Config.Msi\2d960.rbs
- %WINDIR%\Installer\2d95f.ipi
- %WINDIR%\Installer\2d95e.msi
- %WINDIR%\Installer\MSI15.tmp
- %WINDIR%\Installer\MSIC.tmp
- %TEMP%\_is4.tmp
- %TEMP%\_is2.tmp
- %TEMP%\_is1.tmp
- %TEMP%\~3.tmp
- %TEMP%\Cab9.tmp
- %TEMP%\Cab7.tmp
- %TEMP%\Cab5.tmp
- 'crl.verisign.com':80
- 'cs######0-crl.verisign.com':80
- 'wp#d':80
- 'www.download.windowsupdate.com':80
- crl.verisign.com/pca3.crl
- crl.verisign.com/pca3-g5.crl
- cs######0-crl.verisign.com/CSC3-2010.crl
- wp#d/wpad.dat
- www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
- www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- DNS ASK crl.verisign.com
- DNS ASK cs######0-crl.verisign.com
- DNS ASK wp#d
- DNS ASK www.download.windowsupdate.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''