Threat Database Trojans Trojan.Dropper.Agent.DT

Trojan.Dropper.Agent.DT

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,694
Threat Level: 80 % (High)
Infected Computers: 1
First Seen: March 17, 2026
Last Seen: July 23, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Dropper.Agent.DT
Signature status: No Signature

Known Samples

MD5: 2b8aee36442f48f26ea8fa756dfb086b
SHA1: 651f996df543845edc39e1a93bbd46d62335c323
SHA256: F507AC7D23BB4E553DE1397A3C5CFE49738D55482F6D03675CAD7A347609A517
File Size: 130.36 KB, 130364 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Meridian Cloud Services
File Description Runtime Environment Host
File Version 10.1.9349.789
Internal Name rthost.exe
Legal Copyright Copyright (C) 2026 Meridian Cloud Services
Original Filename rthost.exe
Product Name Cloud Sync Platform
Product Version 10.1.9349.789

File Traits

  • x64

Block Information

Total Blocks: 247
Potentially Malicious Blocks: 96
Whitelisted Blocks: 151
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x 0 x 0 x 0 x x x x 0 x 0 x x x 0 x x x x x x 0 0 x x x 0 x x x x x x x x x x 0 x 0 x 0 0 0 0 x 0 x 0 x 0 x x x x x 0 x x x 0 x 0 0 x x x x x x x x x x x 0 x x 0 0 x x x 0 x 0 x 0 x x 0 x x x 0 x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Dropper.Agent.DT
  • Trojan.Agent.Gen.DYO

Files Modified

File Attributes
c:\users\user\appdata\local\temp\~df00753f80.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0075401d.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df007a53db.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df007e6992.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df007f2c4b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00840b7b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0088fd4b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df008c264b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df008de23b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0092b4fb.tmp Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\~df00978f17.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0099e3df.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df009c6c8a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00a14d8b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00a62b4b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00a7a05a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00ab1f8b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00b001cb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00b4d49b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00b55ce4.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00b9bc3a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00be987b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00c319ad.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00c3725b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00c84a4b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00cd34fb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00d0d638.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00d21c4b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00d6f09b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00dbe0ab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00de92d2.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00e0b9db.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00e5a93a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00ea819a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00ec4f6c.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00ef57fb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00f4358b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00f91a8b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00fa0c54.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df00fe00eb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0102f4ea.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0107c8ee.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0107d36b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df010cb163.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df011199fa.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01158614.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df011677ab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df011b5beb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0120323b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df012342be.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0125078b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0129eafb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df012ec79a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0133a20b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df013880ba.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df013d5b3a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df014240fb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df014734ab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df014c0f3b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0150df6b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0155bbdb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df015a8b4b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df015f741a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01645fab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df016946ab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df016e1e0b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0173047b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0177f04b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df017cd49b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0181c16b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0186a7eb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df018b762b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0190598b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01953c2b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df019a1dbb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df019f04cb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01a3f76a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01a8d30b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01adb10b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01b290fb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01b77c7b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01bc62ed.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01c137ab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01c60e2b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01cafb5a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01cfed6b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01d4d04b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01d9a67b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01de829b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01e3684b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01e8433b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01ed20ab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01f20cea.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01f6df5b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df01fbc09b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0200917b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0205797b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df020a5d5b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df020f46cb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02142c38.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df021916ab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df021defdb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0222dedb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0227c1fb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df022c9a2b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02317cba.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0236685b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df023b584b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df024036fb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df024523cb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df024a0ddb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df024eea9b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0253cdcb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02589e9b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df025d71ea.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0262529b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df026733db.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df026c1c1b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0270fe49.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0275e92b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df027ac30b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df027fa26b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0284820b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02895f1b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df028e5a6a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02933deb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02981dfb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df029ced37.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02a1d0ab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02a6b79b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02ab9ceb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02b08c37.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02b56fab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02ba4c2a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02bf2d2b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02c40c9b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02c8f35b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02cdd45b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02d2aa4a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02d7895b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02dc5e3b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02e1441b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02e6259b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02eb0c4b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02efdfdb.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02f4bbab.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02f99f1b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df02fe767a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0303582b.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~df0308375b.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\edgeupdate Synchronize,Write Attributes
c:\users\user\appdata\roaming\edgeupdate\msedgeupdate.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\edgeupdate\msedgeupdate.exe Synchronize,Write Attributes
c:\users\user\appdata\roaming\windowshelper Synchronize,Write Attributes
c:\users\user\appdata\roaming\windowshelper\svchost32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\windowshelper\svchost32.exe Synchronize,Write Attributes
c:\users\user\appdata\roaming\windowshelper\winsyncprovider.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
Show More
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32:: C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\WinSyncProvider.dll RegNtPreCreateKey
HKCU\clsid\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\inprocserver32::threadingmodel Both RegNtPreCreateKey

98 additional registry modifications are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
Show More
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerName
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
Encryption Used
  • BCryptOpenAlgorithmProvider
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetSetOption
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
  • socket

Shell Command Execution

schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00753f80.tmp" /f
"C:\Users\Vpdwcdqe\AppData\Roaming\WindowsHelper\svchost32.exe" --cleanup "c:\users\user\downloads\651f996df543845edc39e1a93bbd46d62335c323_0000130364"
"C:\Users\Vpdwcdqe\AppData\Roaming\EdgeUpdate\msedgeupdate.exe" --watchdog
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0075401d.tmp" /f
Show More
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df007a53db.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df007f2c4b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00840b7b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0088fd4b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df008de23b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0092b4fb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00978f17.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df009c6c8a.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00a14d8b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00a62b4b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00ab1f8b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00b001cb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df007e6992.tmp" /f
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00b4d49b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00b9bc3a.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00be987b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00c3725b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00c84a4b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00cd34fb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00d21c4b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00d6f09b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00dbe0ab.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df008c264b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00e0b9db.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00e5a93a.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00ea819a.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00ef57fb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00f4358b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00f91a8b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00fe00eb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0099e3df.tmp" /f
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0102f4ea.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0107d36b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df010cb163.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df011199fa.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df011677ab.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df011b5beb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0120323b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0125078b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0129eafb.tmp" /f
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00a7a05a.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df012ec79a.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0133a20b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df013880ba.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df013d5b3a.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df014240fb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df014734ab.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df014c0f3b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0150df6b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00b55ce4.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0155bbdb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df015a8b4b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df015f741a.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df01645fab.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df016946ab.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df016e1e0b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0173047b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0177f04b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df017cd49b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00c319ad.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0181c16b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0186a7eb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df018b762b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df0190598b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df01953c2b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df019a1dbb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df019f04cb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df01a3f76a.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df01a8d30b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df00d0d638.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df01adb10b.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL
schtasks.exe /create /tn "MicrosoftEdgeUpdateBase" /xml "C:\Users\Vpdwcdqe\AppData\Local\Temp\~df01b290fb.tmp" /f
schtasks /query /tn "MicrosoftEdgeUpdateBase" >NUL 2>NUL

151 additional execution are not displayed above.