Source: C:\Windows\System32\msiexec.exe | File opened: z: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: x: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: v: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: t: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: r: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: p: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: n: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: l: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: j: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: h: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: f: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: b: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: y: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: w: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: u: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: s: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: q: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: o: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: m: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: k: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: i: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: g: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: e: | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | File opened: c: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: a: | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_0208F2A0 FindFirstFileW, | 10_2_0208F2A0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_6BE54DD0 FindFirstFileW,FindClose, | 10_2_6BE54DD0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_6BE54650 FindFirstFileW,FindClose,lstrlenW,lstrlenW, | 10_2_6BE54650 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD4790 WideCharToMultiByte,WideCharToMultiByte,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindNextFileW,FindClose, | 10_2_000000013FBD4790 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF43C4 FindFirstFileExW, | 10_2_000000013FBF43C4 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FE494A GetFileAttributesW,FindFirstFileW,FindClose, | 11_2_00FE494A |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FE4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_00FE4005 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FEC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_00FEC2FF |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FECD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 11_2_00FECD9F |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FECD14 FindFirstFileW,FindClose, | 11_2_00FECD14 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FEF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_00FEF5D8 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FEF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_00FEF735 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FEFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_00FEFA36 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FE3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_00FE3CE2 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C6A68C FindFirstFileW,FindNextFileW,FindClose, | 11_2_04C6A68C |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C692A4 FindFirstFileW,lstrcmpW,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FindNextFileW,FindClose, | 11_2_04C692A4 |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: files.cab.5.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://ocsp.digicert.com0 |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://www.apple.com/ |
Source: iTunesHelper.exe, 0000000A.00000002.510465990.000000000039F000.00000004.00000020.00020000.00000000.sdmp, iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe, 0000000B.00000000.412214150.0000000001049000.00000002.00000001.01000000.00000009.sdmp, Autoit3.exe.10.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: test.msi, files.cab.5.dr | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: Autoit3.exe, 0000000B.00000002.414032605.0000000003827000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://mail.google.com/mail/u/0/#inbox |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Autoit3.exe.10.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: iTunesHelper.exe, 0000000A.00000003.411992213.000007FFFE663000.00000004.00001000.00020000.00000000.sdmp, Autoit3.exe.10.dr | String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FF4632 OpenClipboard,IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetClipboardData,CloseClipboard,GlobalLock,CloseClipboard,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,DragQueryFileW,DragQueryFileW,DragQueryFileW,GlobalUnlock,CountClipboardFormats,CloseClipboard, | 11_2_00FF4632 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FF4632 OpenClipboard,IsClipboardFormatAvailable,IsClipboardFormatAvailable,GetClipboardData,CloseClipboard,GlobalLock,CloseClipboard,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalUnlock,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,DragQueryFileW,DragQueryFileW,DragQueryFileW,GlobalUnlock,CountClipboardFormats,CloseClipboard, | 11_2_00FF4632 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C4B220 GetObjectA,GetDC,CreateCompatibleDC,CreateBitmap,CreateCompatibleBitmap,GetDeviceCaps,GetDeviceCaps,SelectObject,GetDIBColorTable,GetDIBits,SelectObject,CreateDIBSection,GetDIBits,SelectObject,SelectPalette,RealizePalette,FillRect,SetTextColor,SetBkColor,SetDIBColorTable,CreateCompatibleDC,SelectObject,SelectPalette,RealizePalette,SetTextColor,SetBkColor,BitBlt,SelectPalette,SelectObject,DeleteDC,SelectPalette, | 11_2_04C4B220 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_0100D164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 11_2_0100D164 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C62CC4 NtDuplicateObject,NtClose,NtClose,NtClose,NtClose,NtClose,NtClose,NtClose, | 11_2_04C62CC4 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C62C1C NtQueryObject, | 11_2_04C62C1C |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C62F68 Sleep,NtClose,NtClose, | 11_2_04C62F68 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C62BE8 NtDuplicateObject,NtClose, | 11_2_04C62BE8 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C39934 GetCurrentProcessId,CreateProcessA,NtQueryInformationProcess,ReadProcessMemory,ReadProcessMemory,WriteProcessMemory,ResumeThread,Sleep,GetTickCount, | 11_2_04C39934 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_0208ED60 | 10_2_0208ED60 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_02092AA0 | 10_2_02092AA0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_6BE54890 | 10_2_6BE54890 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_6BE6F350 | 10_2_6BE6F350 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD1720 | 10_2_000000013FBD1720 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF2F4C | 10_2_000000013FBF2F4C |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD3670 | 10_2_000000013FBD3670 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE9EC8 | 10_2_000000013FBE9EC8 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE46C0 | 10_2_000000013FBE46C0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE6EAC | 10_2_000000013FBE6EAC |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE2E0C | 10_2_000000013FBE2E0C |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD2E00 | 10_2_000000013FBD2E00 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE25EC | 10_2_000000013FBE25EC |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF0E34 | 10_2_000000013FBF0E34 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF351C | 10_2_000000013FBF351C |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD5510 | 10_2_000000013FBD5510 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE8CE4 | 10_2_000000013FBE8CE4 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF2CD0 | 10_2_000000013FBF2CD0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE2C08 | 10_2_000000013FBE2C08 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF73F8 | 10_2_000000013FBF73F8 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE23E8 | 10_2_000000013FBE23E8 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBEA3D4 | 10_2_000000013FBEA3D4 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD53D0 | 10_2_000000013FBD53D0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF43C4 | 10_2_000000013FBF43C4 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBFC308 | 10_2_000000013FBFC308 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBEC300 | 10_2_000000013FBEC300 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF12C8 | 10_2_000000013FBF12C8 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE42BC | 10_2_000000013FBE42BC |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD92B0 | 10_2_000000013FBD92B0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE29FC | 10_2_000000013FBE29FC |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD51D0 | 10_2_000000013FBD51D0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF1948 | 10_2_000000013FBF1948 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBEC940 | 10_2_000000013FBEC940 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE3928 | 10_2_000000013FBE3928 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD40A0 | 10_2_000000013FBD40A0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBEF068 | 10_2_000000013FBEF068 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBE27F8 | 10_2_000000013FBE27F8 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD5830 | 10_2_000000013FBD5830 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FA33B7 | 11_2_00FA33B7 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F894E0 | 11_2_00F894E0 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F81663 | 11_2_00F81663 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F89C80 | 11_2_00F89C80 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FA23F5 | 11_2_00FA23F5 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_01008400 | 11_2_01008400 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FB6502 | 11_2_00FB6502 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F8E6F0 | 11_2_00F8E6F0 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FB265E | 11_2_00FB265E |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FA282A | 11_2_00FA282A |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FB89BF | 11_2_00FB89BF |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FB6A74 | 11_2_00FB6A74 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F90BE0 | 11_2_00F90BE0 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_01000A3A | 11_2_01000A3A |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FDEDB2 | 11_2_00FDEDB2 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FACD51 | 11_2_00FACD51 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FE8E44 | 11_2_00FE8E44 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FB6FE6 | 11_2_00FB6FE6 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_01000EB7 | 11_2_01000EB7 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F8B020 | 11_2_00F8B020 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F9D45D | 11_2_00F9D45D |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FAF409 | 11_2_00FAF409 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FA16B4 | 11_2_00FA16B4 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F8F6A0 | 11_2_00F8F6A0 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F9F628 | 11_2_00F9F628 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FA78C3 | 11_2_00FA78C3 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FA1BA8 | 11_2_00FA1BA8 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FADBA5 | 11_2_00FADBA5 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FB9CE5 | 11_2_00FB9CE5 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F9DD28 | 11_2_00F9DD28 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FABFD6 | 11_2_00FABFD6 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FA1FC0 | 11_2_00FA1FC0 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C4EC98 | 11_2_04C4EC98 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C38E2C | 11_2_04C38E2C |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C35610 | 11_2_04C35610 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C5B250 | 11_2_04C5B250 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C59C68 | 11_2_04C59C68 |
Source: C:\temp\Autoit3.exe | Code function: String function: 04C444F8 appears 31 times | |
Source: C:\temp\Autoit3.exe | Code function: String function: 00FA8B30 appears 42 times | |
Source: C:\temp\Autoit3.exe | Code function: String function: 04C16A4C appears 111 times | |
Source: C:\temp\Autoit3.exe | Code function: String function: 00FA0D17 appears 70 times | |
Source: C:\temp\Autoit3.exe | Code function: String function: 00F91A36 appears 34 times | |
Source: C:\temp\Autoit3.exe | Code function: String function: 04C14724 appears 52 times | |
Source: C:\temp\Autoit3.exe | Code function: String function: 04C14450 appears 104 times | |
Source: C:\temp\Autoit3.exe | Code function: String function: 04C149C0 appears 86 times | |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: String function: 000000013FBD5F60 appears 32 times | |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rpcrtremote.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msihnd.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rpcrtremote.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: spp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vssapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vsstrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: dsrole.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: bcrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wow64win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wow64cpu.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: rpcrtremote.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: devrtl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Section loaded: wow64win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Section loaded: wow64cpu.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\expand.exe | Section loaded: wow64win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\expand.exe | Section loaded: wow64cpu.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\expand.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\expand.exe | Section loaded: dpx.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\expand.exe | Section loaded: wdscore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Section loaded: corefoundation.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: wow64win.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: wow64cpu.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\temp\Autoit3.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wow64win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wow64cpu.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: winbrand.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Section loaded: wow64win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Section loaded: wow64cpu.dll | Jump to behavior |
Source: metadata-2.2.dr | Binary string: highlight.png22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\66program files\windows sidebar\gadgets\rssfeeds.gadgeticon.png22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\QQprogramdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0} |
Source: metadata-2.2.dr | Binary string: wmplayer.exe.mui22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\BBprogram files (x86)\windows sidebar\gadgets\weather.gadget\images**undocked_black_moon-new_partly-cloudy.png22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\((windows\diagnostics\system\device\en-us |
Source: metadata-2.2.dr | Binary string: buttonup_off.png22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\QQprogramdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0} |
Source: metadata-2.2.dr | Binary string: system.web.dynamicdata.dll22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\BBprogram files (x86)\windows sidebar\gadgets\weather.gadget\images33docked_black_moon-waxing-gibbous_partly-cloudy.png22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\QQprogramdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120} |
Source: metadata-2.2.dr | Binary string: system.addin.contract.dll22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\QQprogramdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0} |
Source: metadata-2.2.dr | Binary string: btn-previous-static.png22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\QQprogramdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120} |
Source: metadata-2.2.dr | Binary string: keypad.xml22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\99program files\dvd maker\shared\dvdstyles\specialoccasion,,specialnavigationup_selectionsubpicture.png22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\QQprogramdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120} |
Source: metadata-2.2.dr | Binary string: scenes_intro_bg_pal.wmv22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\QQprogramdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0} |
Source: metadata-2.2.dr | Binary string: acxtrnal.dll22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\((windows\diagnostics\system\device\en-us |
Source: metadata-2.2.dr | Binary string: sbdrop.dll22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\QQprogramdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0} |
Source: C:\Windows\SysWOW64\icacls.exe | Console Write: ......................$......... 4......(.P.....L.......T.......................................0...............................p. ....... ..... | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Console Write: ......................$......... 4......(.P.....L.......T...............%.......................0.......................v.................$..... | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Console Write: ................P.......................(.P..............................$......................................................N..s............ | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Console Write: ................P...............:. .....(.P..............................$......................................x............................... | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Console Write: ................................ 4#.....(.P..............................$..............................................X....................... | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Console Write: ................................ 4#.....(.P..............................$..............................................v....................... | Jump to behavior |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\test.msi" | |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 5F18B271DCB7565374F8A7B6F18643C9 | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\system32\ICACLS.EXE" "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\." /SETINTEGRITYLEVEL (CI)(OI)HIGH | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\expand.exe "C:\Windows\system32\EXPAND.EXE" -R files.cab -F:* files | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe" | |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Process created: C:\temp\Autoit3.exe "c:\temp\Autoit3.exe" c:\temp\script.a3x | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c rd /s /q "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files" | |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\system32\ICACLS.EXE" "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\." /SETINTEGRITYLEVEL (CI)(OI)LOW | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 5F18B271DCB7565374F8A7B6F18643C9 | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\system32\ICACLS.EXE" "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\." /SETINTEGRITYLEVEL (CI)(OI)HIGH | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\expand.exe "C:\Windows\system32\EXPAND.EXE" -R files.cab -F:* files | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c rd /s /q "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files" | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\system32\ICACLS.EXE" "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\." /SETINTEGRITYLEVEL (CI)(OI)LOW | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Process created: C:\temp\Autoit3.exe "c:\temp\Autoit3.exe" c:\temp\script.a3x | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FC150E0 push rbx; retf | 10_2_000000013FC150E1 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FA8B75 push ecx; ret | 11_2_00FA8B88 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_0381E7B9 push 0381E7E7h; ret | 11_2_0381E7DF |
Source: C:\temp\Autoit3.exe | Code function: 11_2_0381E7C1 push 0381E7E7h; ret | 11_2_0381E7DF |
Source: C:\temp\Autoit3.exe | Code function: 11_2_0381DFDD push 0381E009h; ret | 11_2_0381E001 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_0381DF19 push 0381DF51h; ret | 11_2_0381DF49 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_0381DF5D push 0381DF89h; ret | 11_2_0381DF81 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_0381DD75 push 0381DDAFh; ret | 11_2_0381DDA7 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C3C4D8 push 04C3C504h; ret | 11_2_04C3C4FC |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C3E4B8 push 04C3E504h; ret | 11_2_04C3E4FC |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C20418 push 04C20444h; ret | 11_2_04C2043C |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C165D0 push 04C16621h; ret | 11_2_04C16619 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C64588 push 04C645BBh; ret | 11_2_04C645B3 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C68538 push 04C68564h; ret | 11_2_04C6855C |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C68690 push 04C686BCh; ret | 11_2_04C686B4 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C64604 push 04C64630h; ret | 11_2_04C64628 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C68620 push 04C6864Ch; ret | 11_2_04C68644 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C38634 push 04C3869Ch; ret | 11_2_04C38694 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C627D8 push 04C62804h; ret | 11_2_04C627FC |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C267A8 push 04C26850h; ret | 11_2_04C26848 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C3C710 push 04C3C73Ch; ret | 11_2_04C3C734 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C6C71C push 04C6C742h; ret | 11_2_04C6C73A |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C26730 push 04C267A6h; ret | 11_2_04C2679E |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C2E034 push 04C2E0A3h; ret | 11_2_04C2E09B |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C2C034 push ecx; mov dword ptr [esp], 0000001Ch | 11_2_04C2C035 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C4215C push 04C42194h; ret | 11_2_04C4218C |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C68158 push 04C681AFh; ret | 11_2_04C681A7 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C62114 push 04C6217Ch; ret | 11_2_04C62174 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C683BC push 04C683FEh; ret | 11_2_04C683F6 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C2A308 push ecx; mov dword ptr [esp], edx | 11_2_04C2A30A |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C3CCC0 push 04C3CD02h; ret | 11_2_04C3CCFA |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | File created: C:\temp\Autoit3.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\expand.exe | File created: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\CoreFoundation.dll (copy) | Jump to dropped file |
Source: C:\Windows\SysWOW64\expand.exe | File created: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\$dpx$.tmp\642bddc38bf301459161108c3729c2ed.tmp | Jump to dropped file |
Source: C:\Windows\SysWOW64\expand.exe | File created: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\$dpx$.tmp\4cd6e0f52e7043469984c6056cd7318a.tmp | Jump to dropped file |
Source: C:\Windows\SysWOW64\expand.exe | File created: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe (copy) | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI7956.tmp | Jump to dropped file |
Source: C:\temp\Autoit3.exe | Code function: 11_2_010059B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, | 11_2_010059B3 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00F95EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, | 11_2_00F95EDA |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FA33B7 RtlEncodePointer,__initp_misc_winsig,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, | 11_2_00FA33B7 |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\temp\Autoit3.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_0208F2A0 FindFirstFileW, | 10_2_0208F2A0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_6BE54DD0 FindFirstFileW,FindClose, | 10_2_6BE54DD0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_6BE54650 FindFirstFileW,FindClose,lstrlenW,lstrlenW, | 10_2_6BE54650 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBD4790 WideCharToMultiByte,WideCharToMultiByte,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindNextFileW,FindClose, | 10_2_000000013FBD4790 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBF43C4 FindFirstFileExW, | 10_2_000000013FBF43C4 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FE494A GetFileAttributesW,FindFirstFileW,FindClose, | 11_2_00FE494A |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FE4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_00FE4005 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FEC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_00FEC2FF |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FECD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 11_2_00FECD9F |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FECD14 FindFirstFileW,FindClose, | 11_2_00FECD14 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FEF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_00FEF5D8 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FEF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 11_2_00FEF735 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FEFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 11_2_00FEFA36 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FE3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 11_2_00FE3CE2 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C6A68C FindFirstFileW,FindNextFileW,FindClose, | 11_2_04C6A68C |
Source: C:\temp\Autoit3.exe | Code function: 11_2_04C692A4 FindFirstFileW,lstrcmpW,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FindNextFileW,FindClose, | 11_2_04C692A4 |
Source: Autoit3.exe, 0000000B.00000002.414032605.0000000003827000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: vmware |
Source: Autoit3.exe, Autoit3.exe, 0000000B.00000002.414101277.0000000004C11000.00000040.00001000.00020000.00000000.sdmp, Autoit3.exe, 0000000B.00000002.414032605.0000000003827000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: microsoft hyper-v video |
Source: metadata-2.2.dr | Binary or memory string: lsm.exe22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\--windows\system32\migwiz\replacementmanifests,,microsoft-hyper-v-migration-replacement.man22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\ |
Source: metadata-2.2.dr | Binary or memory string: iasmigplugin-dl.man22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\--windows\system32\migwiz\replacementmanifests33microsoft-hyper-v-client-migration-replacement.man22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\##windows\system32\spp\tokens\ppdlic |
Source: metadata-2.2.dr | Binary or memory string: iasmigplugin-dl.man22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\--windows\syswow64\migwiz\replacementmanifests33microsoft-hyper-v-client-migration-replacement.man22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\,,program files (x86)\internet explorer\en-us |
Source: metadata-2.2.dr | Binary or memory string: imscmig.dll22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\--windows\system32\migwiz\replacementmanifests44microsoft-hyper-v-drivers-migration-replacement.man22\\?\Volume{8049f198-1016-11e7-b87b-806e6f6e6963}\ |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBDAE8C SetUnhandledExceptionFilter, | 10_2_000000013FBDAE8C |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBDACA4 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 10_2_000000013FBDACA4 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBDA2F0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 10_2_000000013FBDA2F0 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: 10_2_000000013FBED8B8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 10_2_000000013FBED8B8 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FAA385 SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 11_2_00FAA385 |
Source: C:\temp\Autoit3.exe | Code function: 11_2_00FAA354 SetUnhandledExceptionFilter, | 11_2_00FAA354 |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 5F18B271DCB7565374F8A7B6F18643C9 | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\system32\ICACLS.EXE" "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\." /SETINTEGRITYLEVEL (CI)(OI)HIGH | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\expand.exe "C:\Windows\system32\EXPAND.EXE" -R files.cab -F:* files | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c rd /s /q "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files" | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\system32\ICACLS.EXE" "C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\." /SETINTEGRITYLEVEL (CI)(OI)LOW | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Process created: C:\temp\Autoit3.exe "c:\temp\Autoit3.exe" c:\temp\script.a3x | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: GetUserDefaultUILanguage,GetLocaleInfoW, | 10_2_6BE54F80 |
Source: C:\Users\user\AppData\Local\Temp\MW-c4073f3e-f9c7-437a-a291-ddb95c099068\files\iTunesHelper.exe | Code function: IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 10_2_6BE54060 |
Source: C:\temp\Autoit3.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 11_2_04C15C08 |
Source: C:\temp\Autoit3.exe | Code function: GetLocaleInfoA, | 11_2_04C1655C |
Source: C:\temp\Autoit3.exe | Code function: GetLocaleInfoA, | 11_2_04C1CC4C |
Source: C:\temp\Autoit3.exe | Code function: GetLocaleInfoA, | 11_2_04C1B630 |
Source: C:\temp\Autoit3.exe | Code function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA, | 11_2_04C15D12 |
Source: Autoit3.exe | Binary or memory string: WIN_81 |
Source: Autoit3.exe | Binary or memory string: WIN_XP |
Source: Autoit3.exe | Binary or memory string: WIN_XPe |
Source: Autoit3.exe | Binary or memory string: WIN_VISTA |
Source: Autoit3.exe | Binary or memory string: WIN_7 |
Source: Autoit3.exe | Binary or memory string: WIN_8 |
Source: Autoit3.exe.10.dr | Binary or memory string: %.3d%S%M%H%m%Y%jX86IA64X64WIN32_NTWIN_10WIN_2016WIN_81WIN_2012R2WIN_2012WIN_8WIN_2008R2WIN_7WIN_2008WIN_VISTAWIN_2003WIN_XPeWIN_XPInstallLanguageSYSTEM\CurrentControlSet\Control\Nls\LanguageSchemeLangIDControl Panel\Appearance3, 3, 14, 5USERPROFILEUSERDOMAINUSERDNSDOMAINGetSystemWow64DirectoryWSeDebugPrivilege:winapistdcallubyte |