Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] '{246dcb72-b18c-4ab9-9de9-8a996296b01d}' = '"%ALLUSERSPROFILE%\Application Data\Package Cache\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\v...
- C:\Control WiMO\mysql-connector-odbc-5.3.10-win32.msi
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_MACHINE_SAM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- %TEMP%\CabC.tmp
- %WINDIR%\Installer\322f6.ipi
- %TEMP%\CabA.tmp
- %TEMP%\Cab8.tmp
- %WINDIR%\Installer\322f4.msi
- %WINDIR%\Installer\322f3.msi
- <SYSTEM32>\mfcm120u.dll
- <SYSTEM32>\mfcm120.dll
- <SYSTEM32>\mfc120u.dll
- <SYSTEM32>\mfc120rus.dll
- <SYSTEM32>\mfc120kor.dll
- <SYSTEM32>\mfc120jpn.dll
- <SYSTEM32>\mfc120ita.dll
- <SYSTEM32>\mfc120fra.dll
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- %WINDIR%\Installer\322ea.msi
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\Repository\FS\INDEX.BTR
- %TEMP%\MSI4338f.LOG
- %ProgramFiles%\MySQL\Connector ODBC 5.3\README.txt
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc5w.pdb
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc5w.lib
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc5a.pdb
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc5a.lib
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc5w.dll
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc5S.pdb
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc5S.lib
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc5S.dll
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc5a.dll
- %ProgramFiles%\MySQL\Connector ODBC 5.3\COPYING.txt
- %ProgramFiles%\MySQL\Connector ODBC 5.3\Licenses_for_Third-Party_Components.txt
- <SYSTEM32>\mfc120esn.dll
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\Repository\$WinMgmt.CFG
- %ProgramFiles%\MySQL\Connector ODBC 5.3\ChangeLog.txt
- %TEMP%\Cab16.tmp
- %TEMP%\Cab14.tmp
- %TEMP%\Cab12.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\fifo.log
- %TEMP%\Cab10.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\Repository\FS\OBJECTS.MAP
- C:\Config.Msi\322f7.rbs
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\Repository\FS\OBJECTS.DATA
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\Repository\FS\MAPPING2.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\Repository\FS\MAPPING1.MAP
- %WINDIR%\Installer\MSIE.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\Repository\FS\MAPPING.VER
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc-installer.exe
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP17\snapshot\Repository\FS\INDEX.MAP
- <SYSTEM32>\mfc120enu.dll
- <SYSTEM32>\mfc120deu.dll
- <SYSTEM32>\mfc120cht.dll
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\BootstrapperApplicationData.xml
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.be\vcredist_x86.exe
- %WINDIR%\Installer\322f8.msi
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\license.rtf
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\logo.png
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\thm.wxl
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\thm.xml
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\wixstdba.dll
- %HOMEPATH%\Desktop\Control WiMO.lnk
- C:\Control WiMO\Control WiMO 4.8.84.xlsm
- C:\Control WiMO\CWtitle.ico
- C:\Control WiMO\Install.vbs
- C:\Control WiMO\Open.vbs
- C:\Control WiMO\vcredist_x86.exe
- C:\Control WiMO\Firebird-2.5.8.27089_0_Win32.exe
- C:\Control WiMO\Firebird_ODBC_2.0.5.156_Win32.exe
- %TEMP%\dd_vcredist_x86_20181115051719.log
- %ProgramFiles%\MySQL\Connector ODBC 5.3\myodbc-installer.pdb
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- <SYSTEM32>\mfc120chs.dll
- <SYSTEM32>\mfc120.dll
- C:\Config.Msi\322f2.rbs
- %WINDIR%\Installer\MSI4.tmp
- %WINDIR%\Installer\322f1.ipi
- %WINDIR%\Installer\322ef.msi
- %TEMP%\dd_vcredist_x86_20181115051719_1_vcRuntimeAdditional_x86.log
- %WINDIR%\Installer\322ee.msi
- <SYSTEM32>\vcomp120.dll
- <SYSTEM32>\msvcr120.dll
- <SYSTEM32>\msvcp120.dll
- C:\Config.Msi\322ed.rbs
- %ALLUSERSPROFILE%\Application Data\Package Cache\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\vcredist_x86.exe
- %WINDIR%\Installer\MSI1.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- %TEMP%\dd_vcredist_x86_20181115051719_0_vcRuntimeMinimum_x86.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\cabB3E1576D1FEFBB979E13B1A5379E0B16
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\cab54A5CABBE7274D8A22EB58060AAB7623
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\vcRuntimeAdditional_x86
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\vcRuntimeMinimum_x86
- %ALLUSERSPROFILE%\Application Data\Package Cache\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\state.rsm
- %WINDIR%\Installer\322ec.ipi
- %WINDIR%\Installer\{7EE09EC6-28EB-4FCF-B485-6630E9E5B3F1}\MySQLConnector.ico
- %WINDIR%\Installer\MSI1.tmp
- %WINDIR%\Installer\MSIE.tmp
- %TEMP%\Cab16.tmp
- %TEMP%\Cab14.tmp
- %TEMP%\Cab12.tmp
- %TEMP%\Cab10.tmp
- %TEMP%\CabC.tmp
- %TEMP%\CabA.tmp
- %TEMP%\Cab8.tmp
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\wixstdba.dll
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\thm.xml
- C:\Config.Msi\322f7.rbs
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\thm.wxl
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\license.rtf
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\BootstrapperApplicationData.xml
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.be\vcredist_x86.exe
- %WINDIR%\Installer\322f1.ipi
- %WINDIR%\Installer\322ef.msi
- C:\Config.Msi\322f2.rbs
- %WINDIR%\Installer\MSI4.tmp
- %WINDIR%\Installer\322ec.ipi
- %WINDIR%\Installer\322ea.msi
- C:\Config.Msi\322ed.rbs
- %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.ba1\logo.png
- %WINDIR%\Installer\322f4.msi
- from %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\vcRuntimeMinimum_x86 to %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\vcRuntimeMinimum_x86
- from %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\vcRuntimeMinimum_x86 to %ALLUSERSPROFILE%\Application Data\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi
- from %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\cab54A5CABBE7274D8A22EB58060AAB7623 to %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\cab54A5CABBE7274D8A22EB58060AAB7623
- from %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\cab54A5CABBE7274D8A22EB58060AAB7623 to %ALLUSERSPROFILE%\Application Data\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\cab1.cab
- from %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\vcRuntimeAdditional_x86 to %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\vcRuntimeAdditional_x86
- from %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\vcRuntimeAdditional_x86 to %ALLUSERSPROFILE%\Application Data\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi
- from %TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\cabB3E1576D1FEFBB979E13B1A5379E0B16 to %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\cabB3E1576D1FEFBB979E13B1A5379E0B16
- from %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\cabB3E1576D1FEFBB979E13B1A5379E0B16 to %ALLUSERSPROFILE%\Application Data\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab
- 'wp#d':80
- '20#.#6.232.182':80
- 'download.windowsupdate.com':80
- 'sv.##mcb.com':80
- http://11#.#11.111.1/wpad.dat via wp#d
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl via 20#.#6.232.182
- http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl via 20#.#6.232.182
- http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl via 20#.#6.232.182
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt via download.windowsupdate.com
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab via download.windowsupdate.com
- http://sv.##mcb.com/sv.crt
- DNS ASK wp#d
- DNS ASK sv.##mcb.com
- ClassName: 'EDIT' WindowName: ''
- 'C:\Control WiMO\vcredist_x86.exe' /install /passive /norestart
- '%TEMP%\{246dcb72-b18c-4ab9-9de9-8a996296b01d}\.be\vcredist_x86.exe' -q -burn.elevated BurnPipe.{4F2B3B04-7354-494F-8B43-71F4188C39E5} {147FC6DE-017C-4419-B7D2-B96D4C490F58} 2896
- '<SYSTEM32>\wscript.exe' "C:\Control WiMO\Install.vbs"
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\msiexec.exe' /i mysql-connector-odbc-5.3.10-win32.msi /passive