paperlined.org
apps > sysinternals > procmon_install_logs
document updated 15 years ago, on May 14, 2008
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7623d280-d430-11dc-a835-806d6172696f}\BaseClass
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7623d281-d430-11dc-a835-806d6172696f}\BaseClass
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7623d282-d430-11dc-a835-806d6172696f}\BaseClass
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\BaseClass
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\BaseClass
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\BaseClass
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\nsx870C.tmp
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsx870C.tmp
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp
WinPcap_4_0_2.exe    create directory   D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\UserInfo.dll
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\CACE_Banner.htm
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\CACE_Logo.gif
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\NetSol.jpg
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\ioSpecial.ini
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\modern-wizard.bmp
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\modern-header.bmp
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\nsWeb.dll
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Directory
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Paths
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\CachePath
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\CachePath
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\CachePath
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\CachePath
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\CacheLimit
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\CacheLimit
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\CacheLimit
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\CacheLimit
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\History
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\InstallOptions.dll
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\CACE_Banner.htm
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\CACE_Logo.gif
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\NetSol.jpg
WinPcap_4_0_2.exe    create directory   C:\Program Files\WinPcap\
WinPcap_4_0_2.exe    create file        C:\Program Files\WinPcap\rpcapd.exe
WinPcap_4_0_2.exe    create file        C:\Program Files\WinPcap\WinPcapInstall.dll
WinPcap_4_0_2.exe    create file        C:\WINDOWS\system32\wpcap.dll
WinPcap_4_0_2.exe    create file        C:\WINDOWS\system32\pthreadVC.dll
WinPcap_4_0_2.exe    create file        C:\WINDOWS\system32\Packet.dll
WinPcap_4_0_2.exe    create file        C:\WINDOWS\system32\WanPacket.dll
WinPcap_4_0_2.exe    create file        C:\WINDOWS\system32\drivers\npf.sys
WinPcap_4_0_2.exe    create file        D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\System.dll
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Network\NetCfgLockHolder\(Default)
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@netcfgx.dll,-50003
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@netcfgx.dll,-50002
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@netcfgx.dll,-50020
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@netcfgx.dll,-50001
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Network\Config
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0013\Linkage\Export
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0013\Linkage\RootDevice
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0013\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{E686A895-BD36-45D9-968E-FCD023FE319B}\UpperBindings
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0009\NetCfgInstanceId
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0009\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0014\Linkage\Export
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0014\Linkage\RootDevice
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0014\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\NdisWanBh\UpperBindings
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0008\NetCfgInstanceId
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0008\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0015\Linkage\Export
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0015\Linkage\RootDevice
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0015\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\NdisWanIp\UpperBindings
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0007\NetCfgInstanceId
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0007\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0018\Linkage\Export
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0018\Linkage\RootDevice
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0018\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{4D5D0464-E671-4F70-AA27-5AC16C842C29}\UpperBindings
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0016\NetCfgInstanceId
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0016\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0017\Linkage\Export
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0017\Linkage\RootDevice
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0017\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{E9D9F944-258A-48F7-AC4A-FD253371C8B0}\UpperBindings
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0019\NetCfgInstanceId
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0019\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0021\Linkage\Export
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0021\Linkage\RootDevice
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0021\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{02C0DC6E-671E-4F40-8C76-7C40A2235C73}\UpperBindings
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0020\NetCfgInstanceId
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0020\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0012\Linkage\Export
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0012\Linkage\RootDevice
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0012\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{C4F18899-880D-44DA-8A1C-67F769F86FE0}\UpperBindings
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0011\NetCfgInstanceId
WinPcap_4_0_2.exe    reg write          HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0011\Linkage\UpperBind
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\WinPcap\(Default)
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\DisplayName
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\UninstallString
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\Publisher
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\URLInfoAbout
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\URLUpdateInfo
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\VersionMajor
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\VersionMinor
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\DisplayVersion
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Programs
WinPcap_4_0_2.exe    create directory   D:\Profiles\All Users\Start Menu\Programs\WinPcap\
WinPcap_4_0_2.exe    create file        D:\Profiles\All Users\Start Menu\Programs\WinPcap\WinPcap Web Site.url
WinPcap_4_0_2.exe    create file        D:\Profiles\All Users\Start Menu\Programs\WinPcap\Uninstall WinPcap 4.0.2.lnk
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Desktop
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Start Menu
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start Menu
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Desktop
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppData
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Pictures
WinPcap_4_0_2.exe    reg write          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Personal
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonPictures
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Documents
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonMusic
WinPcap_4_0_2.exe    reg write          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonVideo
WinPcap_4_0_2.exe    create file        C:\Program Files\WinPcap\Uninstall.exe
WinPcap_4_0_2.exe    delete             C:\Program Files\WinPcap\WinPcapInstall.dll
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\InstallOptions.dll
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\ioSpecial.ini
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\modern-header.bmp
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\modern-wizard.bmp
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\nsWeb.dll
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\System.dll
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\UserInfo.dll
WinPcap_4_0_2.exe    delete             D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp