Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, jli.dll.0.dr, libcef.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertEVCodeSigningCA.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: setup#U67e5#U8be2_pf2024.exe, Lua51.dll.0.dr | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0X |
Source: setup#U67e5#U8be2_pf2024.exe, Lua51.dll.0.dr | String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr, winPre2k.iso.0.dr | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08 |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, jli.dll.0.dr, libcef.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/EVCodeSigning-g1.crl03 |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/assured-cs-g1.crl00 |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, jli.dll.0.dr, libcef.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, jli.dll.0.dr, libcef.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/EVCodeSigning-g1.crl0K |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/assured-cs-g1.crl0L |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, jli.dll.0.dr, libcef.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, jli.dll.0.dr, libcef.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0H |
Source: setup#U67e5#U8be2_pf2024.exe, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0I |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0L |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0N |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, jli.dll.0.dr, libcef.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0O |
Source: setup#U67e5#U8be2_pf2024.exe, adapt_for_imports.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: setup#U67e5#U8be2_pf2024.exe, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr, winPre2k.iso.0.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr | String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr | String found in binary or memory: http://s2.symcb.com0 |
Source: setup#U67e5#U8be2_pf2024.exe, Lua51.dll.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, Lua51.dll.0.dr | String found in binary or memory: http://sf.symcb.com/sf.crl0a |
Source: setup#U67e5#U8be2_pf2024.exe, Lua51.dll.0.dr | String found in binary or memory: http://sf.symcb.com/sf.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, Lua51.dll.0.dr | String found in binary or memory: http://sf.symcd.com0& |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr | String found in binary or memory: http://sv.symcb.com/sv.crl0a |
Source: setup#U67e5#U8be2_pf2024.exe, kill.exe.0.dr | String found in binary or memory: http://sv.symcb.com/sv.crl0f |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr | String found in binary or memory: http://sv.symcb.com/sv.crt0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr | String found in binary or memory: http://sv.symcd.com0& |
Source: setup#U67e5#U8be2_pf2024.exe, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr, winPre2k.iso.0.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: setup#U67e5#U8be2_pf2024.exe, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr, winPre2k.iso.0.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: setup#U67e5#U8be2_pf2024.exe, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr, winPre2k.iso.0.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: setup#U67e5#U8be2_pf2024.exe, Wegame.exe.0.dr | String found in binary or memory: http://ue.qq.com/mur/?a=survey&b=15087&c=1&d=15272af955762c32696995ddcabc396a |
Source: setup#U67e5#U8be2_pf2024.exe, Wegame.exe.0.dr | String found in binary or memory: http://ue.qq.com/mur/?a=survey&b=15087&c=1&d=15272af955762c32696995ddcabc396a-s-f |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, jli.dll.0.dr, libcef.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0 |
Source: setup#U67e5#U8be2_pf2024.exe, RuntimeBroker.exe.0.dr | String found in binary or memory: http://www.google.com |
Source: setup#U67e5#U8be2_pf2024.exe, RuntimeBroker.exe.0.dr | String found in binary or memory: http://www.google.comcefsimplestring |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr | String found in binary or memory: http://www.symauth.com/cps0( |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr | String found in binary or memory: http://www.symauth.com/rpa00 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, winPre2k.iso.0.dr | String found in binary or memory: http://www.vmware.com/0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr | String found in binary or memory: http://www.vmware.com/0/ |
Source: wm.exe.0.dr | String found in binary or memory: http://www.vmware.com/go/vcloud_login |
Source: setup#U67e5#U8be2_pf2024.exe, winPre2k.iso.0.dr | String found in binary or memory: http://www.vmware.com/support/reference/common/info_tools.html. |
Source: setup#U67e5#U8be2_pf2024.exe, Wegame.exe.0.dr | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: setup#U67e5#U8be2_pf2024.exe, Wegame.exe.0.dr | String found in binary or memory: http://www.winimage.com/zLibDll1.2.5 |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2246415889.0000000001FE5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chengwangbaikou-1322151504.cos.ap-beijing.myqcloud.com/ |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: https://chengwangbaikou-1322151504.cos.ap-beijing.myqcloud.com/guofucheng.txt |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2246415889.0000000002019000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chengwangbaikou-1322151504.cos.ap-beijing.myqcloud.com/guofucheng.txtPF |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2246646530.0000000003A60000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chengwangbaikou-1322151504.cos.ap-beijing.myqcloud.com/guofucheng.txtl |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2246415889.0000000002019000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chengwangbaikou-1322151504.cos.ap-beijing.myqcloud.com/guofucheng.txtmF |
Source: setup#U67e5#U8be2_pf2024.exe, common.dll.0.dr | String found in binary or memory: https://curl.haxx.se/docs/http-cookies.html |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr | String found in binary or memory: https://d.symcb.com/cps0% |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, kill.exe.0.dr, RuntimeBroker.exe.0.dr, Lua51.dll.0.dr | String found in binary or memory: https://d.symcb.com/rpa0 |
Source: setup#U67e5#U8be2_pf2024.exe, wm.exe.0.dr, adapt_for_imports.dll.0.dr, jli.dll.0.dr, libcef.dll.0.dr, Wegame.exe.0.dr, common.dll.0.dr | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: setup#U67e5#U8be2_pf2024.exe, Lua51.dll.0.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: setup#U67e5#U8be2_pf2024.exe, Lua51.dll.0.dr | String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: setup#U67e5#U8be2_pf2024.exe, RuntimeBroker.exe.0.dr | String found in binary or memory: https://www.xiami.com/0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00424050 | 3_2_00424050 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00458223 | 3_2_00458223 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_004062C0 | 3_2_004062C0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_0042E420 | 3_2_0042E420 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00424490 | 3_2_00424490 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_0042E690 | 3_2_0042E690 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_004246B0 | 3_2_004246B0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_0041E740 | 3_2_0041E740 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_0042C740 | 3_2_0042C740 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00432860 | 3_2_00432860 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00430870 | 3_2_00430870 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_0042E8B0 | 3_2_0042E8B0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_004369A0 | 3_2_004369A0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00428AE0 | 3_2_00428AE0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00422B50 | 3_2_00422B50 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00438D60 | 3_2_00438D60 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00426F40 | 3_2_00426F40 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00424F20 | 3_2_00424F20 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00429208 | 3_2_00429208 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_004312F0 | 3_2_004312F0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00429453 | 3_2_00429453 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00405500 | 3_2_00405500 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00423610 | 3_2_00423610 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_0045785A | 3_2_0045785A |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00431820 | 3_2_00431820 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_004379A0 | 3_2_004379A0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_004339B0 | 3_2_004339B0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00457A92 | 3_2_00457A92 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00415C20 | 3_2_00415C20 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00457CBB | 3_2_00457CBB |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00431D00 | 3_2_00431D00 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00419DB0 | 3_2_00419DB0 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_00457F66 | 3_2_00457F66 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_1001B640 | 3_2_1001B640 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_10015780 | 3_2_10015780 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_1001D88D | 3_2_1001D88D |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_10015C74 | 3_2_10015C74 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_10015DBF | 3_2_10015DBF |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_100162BF | 3_2_100162BF |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_10016468 | 3_2_10016468 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_1001655C | 3_2_1001655C |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_10016639 | 3_2_10016639 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_100267A5 | 3_2_100267A5 |
Source: C:\Users\Wegame\Wegame.exe | Code function: 3_2_100167C0 | 3_2_100167C0 |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C4C82 | 4_2_6C7C4C82 |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C05D4 | 4_2_6C7C05D4 |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C15C1 | 4_2_6C7C15C1 |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C6624 | 4_2_6C7C6624 |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C0E07 | 4_2_6C7C0E07 |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C4731 | 4_2_6C7C4731 |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C58AF | 4_2_6C7C58AF |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C11D9 | 4_2_6C7C11D9 |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C51D3 | 4_2_6C7C51D3 |
Source: C:\Users\Statr\kill.exe | Code function: 4_2_6C7C0A69 | 4_2_6C7C0A69 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_0057E230 | 6_2_0057E230 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005F02A9 | 6_2_005F02A9 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_00586430 | 6_2_00586430 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_00598520 | 6_2_00598520 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005DC7A0 | 6_2_005DC7A0 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005DC8DB | 6_2_005DC8DB |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_00596980 | 6_2_00596980 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_00596A10 | 6_2_00596A10 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005F4CF3 | 6_2_005F4CF3 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005DCD6F | 6_2_005DCD6F |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005B0D10 | 6_2_005B0D10 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005A0E90 | 6_2_005A0E90 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005810A5 | 6_2_005810A5 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005DD127 | 6_2_005DD127 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005A1250 | 6_2_005A1250 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_0058F256 | 6_2_0058F256 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005EB22C | 6_2_005EB22C |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005E7330 | 6_2_005E7330 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005DD4FC | 6_2_005DD4FC |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005DD8C1 | 6_2_005DD8C1 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_0057F8B0 | 6_2_0057F8B0 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005D9B29 | 6_2_005D9B29 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_00591B90 | 6_2_00591B90 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005E1D7A | 6_2_005E1D7A |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005EDD0A | 6_2_005EDD0A |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005DDE60 | 6_2_005DDE60 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005EDE37 | 6_2_005EDE37 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_0058BF10 | 6_2_0058BF10 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_005E1FA2 | 6_2_005E1FA2 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_03520031 | 6_2_03520031 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_0352C064 | 6_2_0352C064 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_0352A49D | 6_2_0352A49D |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_0352B4B4 | 6_2_0352B4B4 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_0352B954 | 6_2_0352B954 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_0352BDD4 | 6_2_0352BDD4 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_03529D8F | 6_2_03529D8F |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_03529CE3 | 6_2_03529CE3 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_10009899 | 6_2_10009899 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_1000A8B0 | 6_2_1000A8B0 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_1000B1D0 | 6_2_1000B1D0 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_1000B460 | 6_2_1000B460 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_1000AD50 | 6_2_1000AD50 |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_100095EE | 6_2_100095EE |
Source: C:\ProgramData\RuntimeBroker.exe | Code function: 6_2_10008EE0 | 6_2_10008EE0 |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2244374973.00000000014E1000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameSetAllUsers.dllP vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2244374973.00000000014E1000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenamehhupd.exeL vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000000.2075450866.000000000049E000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameWeGame. vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000000.2075450866.000000000049E000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenamepolicytool.exeN vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000000.2075450866.000000000049E000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameD vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000000.2075450866.000000000049E000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenamevmware.exeF vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2244374973.000000000049E000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameWeGame. vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2244374973.000000000049E000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenamepolicytool.exeN vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2244374973.000000000049E000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameD vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2244374973.000000000049E000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenamevmware.exeF vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000001.2077759077.0000000001445000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenametoolsinstutil.dll: vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2246839642.00000000046A0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameCmd.Exe.MUIj% vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2246839642.00000000046A0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFileName< vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe, 00000000.00000002.2246839642.000000000470C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameWeGame. vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenameWeGame. vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenamepolicytool.exeN vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenameD vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenamevmware.exeF vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenamecacheMod.exe: vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenameMsi.dll,MsiHnd.dll,MsiExec.exeD vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenameMsi.dll,MsiHnd.dll,MsiExec.exeX vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenamesetup.exex, vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenameupgrader.exe: vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenameWEXTRACT.EXE x, vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenametoolsinstutil.dll: vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenameSetAllUsers.dllP vs setup#U67e5#U8be2_pf2024.exe |
Source: setup#U67e5#U8be2_pf2024.exe | Binary or memory string: OriginalFilenamehhupd.exeL vs setup#U67e5#U8be2_pf2024.exe |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: acgenral.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: twext.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: windows.fileexplorer.common.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: shacct.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: idstore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: acppage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: wlidprov.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: provsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: twext.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: acppage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: twext.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: acppage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\setup#U67e5#U8be2_pf2024.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: acgenral.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: adapt_for_imports.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: lua51.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: common.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: msvcp140.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: common.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: msvcp140.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\Wegame\Wegame.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: acgenral.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: jli.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: msvcr100.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Users\Statr\kill.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: acgenral.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: libcef.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: msvcp100.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: msvcr100.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: msvcr100.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: devenum.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: avicap32.dll | Jump to behavior |
Source: C:\ProgramData\RuntimeBroker.exe | Section loaded: msvfw32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: acgenral.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: Wegame.exe | String found in binary or memory: -launcher= |
Source: Wegame.exe | String found in binary or memory: -launcher |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: -launcher= |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: [IsForInstallation]This is a start from install.[IsForInstallation]This is a start from uninstall.[IsForInstallation]This is not a start from install.--debugdebugstamp_recordmain_start[wegame_launch][step1]Main start.-multi_launcher=wegame.exewegamex.exemulti_launcher_TGP_EXISTS_MUTEX_NAME_[main] wegame already exist.-d-p-ouin=start_from_hostoffline=offline-launcher=[Launcher]Command line game_id not find.launcher_ver[Launcher]Command line version not find.[Launcher]Parser launcher command json fail.[Launcher]Launcher info: %s[Launcher]Launcher parser fail: %s[Launcher]No launcher info.[main]get and set cmd info from cmd_start_info successfullydelete_qb_cookies.txt\clean_cache_flag.dat[CleanCache] need clean page cache.[main]WeGame is in tool mode.[Sys_wrapper]initialize COM library. Error code = %xierd_tgp_daemon.exe[wegame_launch][step2]App inited.app initedbegin...normal end.[main] |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: -launcher |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: Svr_Destory_Tray_IconWeGameCN_Mutex-launcherloop_event_nameZOMBIE-IERD-TGP-31F73356-9B60-ABCD-9FF0-F27E3A9BBEC231F73356-9B60-4B52-9FF0-F27E3A9BBEC2TGP_EXTERNAL_MESSAGE_RECEIVERStaticB15238A8-2061-4a6e-AB8D-F2533B92D794sys_beginsys_ende:\dailybuild_dev\wegame_client\codes\common\src\app.cppcannot set app path, %s[wegame_quit][step1]exit_app:{}.[wegame_quit][step2]exit_app, will_count_:{}[app][Application::process]do_exit_, count:%d, will_count_:%d, can:%s |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: id-cmc-addExtensions |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: set-addPolicy |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: LoadLibraryExA\/AddDllDirectoryauthauth-intauth-confnonce="realm="algorithm=qop="00000001AUTHENTICATEmd5-sessusername="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s,qop=%snoncestalerealmopaqueqopMD5-sessSHA-256SHA-256-SESSSHA-512-256SHA-512-256-SESSuserhash%s:%s:%s%s:%s:%08x:%s:%s:%susername="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=%08x, qop=%s, response="%s"username="%s", realm="%s", nonce="%s", uri="%s", response="%s"%s, opaque="%s"%s, algorithm="%s"%s, userhash=trueOKToo long hexadecimal numberIllegal or missing hexadecimal sequenceMalformed encoding foundWrite errorBad content-encoding found` |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: $Scope-Start-Op Scope-End-Op$Perf-Warning-Op,Monitor-Warning-Op Trace-Task-Op Trace-Expt-OpLEVL@ |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: run-by-unity-helper |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: /?helplocalepower-onpower-on-in-fullscreenfullscreenclose-at-power-offstart-pausedversionversion-textsethostpassworddatacentermoidnew-tabnew-windowbaredisable-ssl-checkingreloadz-order-chillrun-by-unity-helperquery-licensecan-runnew-snunmountnew-vmfeedbackorigin -s There is a space character in your options. Perhaps you are trying to pass two separate options (such as -q -x) in the first line of your configuration file. If so, you need to merge them (-qx).-%cThe option "%s" requires a value. |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: mkisofs 1.15a12 -v -J -R -V VMware Tools -o d:/build/ob/bora-1463223/bora-vmsoft/build/release/install/output/windows.iso d:/build/ob/bora-1463223/bora-vmsoft/build/release/install/winimage |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: d:/build/ob/bora-1463223/bora/apps/install/setup/setup.cpp |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: d:/build/ob/bora-1463223/bora/apps/install/setup/setup.cpp[Info] MsiInstallProduct returned %d --> %s [%Iu][Info] User cancelled installation[Error] %s[Error] The required resource '%s' is missing[Info] Cleaned out installation information for %sHELPER_UIOLDCODESINSTMSIWINSTMSIAinstmsiw.exePROPERTIESinstmsia.exeMINIMUM_NT_MSIMINIMUM_9X_MSISFXINSERTPATCHVM_DATABASELANGUAGESPRODUCTCODEPRODUCTNAMEOPERATION[Info] Will uninstall %s[Info] cacheMod (%s) returned %d" "cacheMod.exe{3B410500-1802-488E-9EF1-4B11992E0440}{B53D42E8-872B-430E-82D4-80065A31FCE1}[Info] Existing product version is older[Info] Existing product version is the same[Info] Existing product version is newer[Info] New product version number is %s[Info] Found existing product %s with version %s[Error] Can't get version for installed product %s (%d)VersionString[Info] Found existing product %s[Info] No existing products found[Info] Checking for existing product %s[Info] Setup exit code is %d[Info] Failed to cleanup extracted files in %s[Info] MsiApplyPatch returned %d and szInstallPackage = {null} and eInstallType = INSTALLTYPE_DEFAULT[Info] Calling MsiApplyPatch with szPatchPackage = %sNOT_REACHED %s:%d |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: change user /INSTALL |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: File_ListDirectory%s\*.*kernel32Schange user /INSTALLSOFTWARE\Microsoft\.NETFramework\policy\v1.1\Microsoft.NET\Framework\v1.1.IsWow64ProcessHKEY_USERSHKEY_LOCAL_MACHINEHKEY_CURRENT_USERHKEY_CURRENT_CONFIGHKEY_CLASSES_ROOT%s: %s%m/%d/%y %H:%M:%S Failed to free module: %dCannot free NULL libraryFreeing library: %dFailed to create key %s: %dFailed to set value: %s\%s\%s: %dCannot query key value %s\%s\%s: %ldCannot open the registry %s\%s: %ldInvalid keyName in Util_CreateKey |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: digt ist.qSetup konnte das Windows-Installationsprogramm nicht auf eine Version aktualisieren, die Schema '%s' unterst |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: ltige Msi-Version. Stellen Sie sicher, dass das Element numerisch ist und mindestens '%d' lautet.\Zur Aktualisierung des Windows-Installationsprogramms sind Administratorrechte erforderlich. |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: Setup kann keine Dateien nach %s extrahieren. Stellen Sie sicher, dass Sie zum Bearbeiten dieses Verzeichnisses berechtigt sind.0Setup konnte die instmsi-Datei '%1'nicht finden.CSetup konnte das Windows-Installationsprogramm nicht aktualisieren. |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: 0PA[Fehler beim Installieren des Pakets. Windows-Installationsprogramm hat '%d' zur |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: r dieses Paket ist eine neuere Version des Windows-Installationsprogramms erforderlich. M |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: chten Sie die Version des Windows-Installationsprogramms auf Ihrem System aktualisieren?aSetup wurde mit einer falschen Betriebsressource '%s' erstellt und kann nicht fortgesetzt werden.& |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: Setup versucht, das Entfernen der Registrierungsinformationen des %s-Installationsprogramms von diesem Computer zu erzwingen. Fahren Sie erst fort, wenn Sie %s auf normalem Weg |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: Setup kann nicht fortgesetzt werden. Das Microsoft-Laufzeit-DLL-Installationsprogramm konnte die Installation nicht abschlie |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: PWD=/cygdrive/d/build/ob/bora-1463223/bora-vmsoft/install/Windows |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: FE2X=C:\Program FilesPROMPT=$P$G$SPWD=/cygdrive/d/build/ob/bora-1463223/bora-vmsoft/install/WindowsPYTHON=D:/build/toolchain/win32/python-2.4.3/python.exePYTHONDONTWRITEBYTECODE=1PYTHONPATH=D:\build\toolchain\noarch\argparse-1.1\lib\python2.6\site-packages;D:\build\apps\gobuild\bin\..RELEASE_BINARIES=d:/build/ob/bora-1463223/publishRELEASE_EXT_PACKAGES=//releng-pa1/current/packagesRELEASE_PACKAGES=d:/build/ob/bora-1463223/publishRELTYPE=GAREMOVE_LOCK=D:/build/toolchain/win32/python-2.6.1/python.exe D:/build/apps/gobuild/bin/gobuildc.py bora-1463223 removelockSCAN_FOR_VIRUSES=1SCMTREESROOT=D:/build/treesSCRIPTNAME=gobuildsSERVERBUILDDIR=d:/build/ob/bora-1463223/bora-vmsoft/build/release/serverSESSIONNAME=ConsoleSHARED_BUILD_MACHINE=1SHELL=D:/build/toolchain/win32/cygwin-1.5.19-4/bin/sh.exeSHLVL=1SIGN_RELEASE_BINARIES=1SIGN_RELEASE_RP<?xml version="1.0" encoding="UTF-8" standalone="yes"?> |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: Attempting to pre-install inf file: "%s" |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: %s change user /INSTALLSOFTWARE\Microsoft\.NETFramework\policy\v1.1\Microsoft.NET\Framework\v1.1.kernel32IsWow64ProcessHKEY_USERSHKEY_LOCAL_MACHINEHKEY_CURRENT_USERHKEY_CURRENT_CONFIGHKEY_CLASSES_ROOTSOFTWARE\VMware, Inc.\VMware Tools\Private%s: %s%m/%d/%y %H:%M:%S Failed to install inf: 0x%08xSuccessfully installed infFailed to get proc address for SetupCopyOEMInfASetupCopyOEMInfAFailed to load setupapi.dll: %dsetupapi.dllAttempting to pre-install inf file: "%s"UpdateDriverForPlugAndPlayDevicesA failed: %dUpdateDriverForPlugAndPlayDevicesA succeededFailed to find UpdateDriverForPlugAndPlayDevicesA: %dUpdateDriverForPlugAndPlayDevicesAFailed to load newdev.dll: %dnewdev.dll...\*NT OS Type is unknown: Major: %i Minor: %iFailed to free module: %dCannot free NULL libraryFreeing library: %dFailed to create key %s: %dFailed to set value: %s\%s\%s: %dCannot query key value %s\%s\%s: %ldCannot open the registry %s\%s: %ldCannot query key value %s\%s\%s: %dInvalid keyName in Util_CreateKey |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: %s change user /INSTALLSOFTWARE\Microsoft\.NETFramework\policy\v1.1\Microsoft.NET\Framework\v1.1.kernel32IsWow64ProcessHKEY_USERSHKEY_LOCAL_MACHINEHKEY_CURRENT_USERHKEY_CURRENT_CONFIGHKEY_CLASSES_ROOTSOFTWARE\VMware, Inc.\VMware Tools\Private%s: %s%m/%d/%y %H:%M:%S Failed to install inf: 0x%08xSuccessfully installed infFailed to get proc address for SetupCopyOEMInfASetupCopyOEMInfAFailed to load setupapi.dll: %dsetupapi.dllAttempting to pre-install inf file: "%s"UpdateDriverForPlugAndPlayDevicesA failed: %dUpdateDriverForPlugAndPlayDevicesA succeededFailed to find UpdateDriverForPlugAndPlayDevicesA: %dUpdateDriverForPlugAndPlayDevicesAFailed to load newdev.dll: %dnewdev.dll...\*NT OS Type is unknown: Major: %i Minor: %iFailed to free module: %dCannot free NULL libraryFreeing library: %dFailed to create key %s: %dFailed to set value: %s\%s\%s: %dCannot query key value %s\%s\%s: %ldCannot open the registry %s\%s: %ldCannot query key value %s\%s\%s: %dInvalid keyName in Util_CreateKey |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: wARNING: Failed to get address for GetProfilesDirectory()GetProfilesDirectoryFailed to load userenv.dll: %duserenv.dllchange user /INSTALLSOFTWARE\Microsoft\.NETFramework\policy\v1.1\Microsoft.NET\Framework\v1.1.kernel32IsWow64ProcessHKEY_USERSHKEY_LOCAL_MACHINEHKEY_CURRENT_USERHKEY_CURRENT_CONFIGHKEY_CLASSES_ROOT%s: %s%m/%d/%y %H:%M:%S Failed to install inf: 0x%08xSuccessfully installed infFailed to get proc address for SetupCopyOEMInfASetupCopyOEMInfAFailed to load setupapi.dll: %dsetupapi.dllAttempting to pre-install inf file: "%s"UpdateDriverForPlugAndPlayDevicesA failed: %dUpdateDriverForPlugAndPlayDevicesA succeededFailed to find UpdateDriverForPlugAndPlayDevicesA: %dUpdateDriverForPlugAndPlayDevicesAFailed to load newdev.dll: %dnewdev.dllNT OS Type is unknown: Major: %i Minor: %iFailed to create key %s: %dFailed to set value: %s\%s\%s: %dCannot query key value %s\%s\%s: %ldCannot open the registry %s\%s: %ldInvalid keyName in Util_CreateKey |
Source: setup#U67e5#U8be2_pf2024.exe | String found in binary or memory: wARNING: Failed to get address for GetProfilesDirectory()GetProfilesDirectoryFailed to load userenv.dll: %duserenv.dllchange user /INSTALLSOFTWARE\Microsoft\.NETFramework\policy\v1.1\Microsoft.NET\Framework\v1.1.kernel32IsWow64ProcessHKEY_USERSHKEY_LOCAL_MACHINEHKEY_CURRENT_USERHKEY_CURRENT_CONFIGHKEY_CLASSES_ROOT%s: %s%m/%d/%y %H:%M:%S Failed to install inf: 0x%08xSuccessfully installed infFailed to get proc address for SetupCopyOEMInfASetupCopyOEMInfAFailed to load setupapi.dll: %dsetupapi.dllAttempting to pre-install inf file: "%s"UpdateDriverForPlugAndPlayDevicesA failed: %dUpdateDriverForPlugAndPlayDevicesA succeededFailed to find UpdateDriverForPlugAndPlayDevicesA: %dUpdateDriverForPlugAndPlayDevicesAFailed to load newdev.dll: %dnewdev.dllNT OS Type is unknown: Major: %i Minor: %iFailed to create key %s: %dFailed to set value: %s\%s\%s: %dCannot query key value %s\%s\%s: %ldCannot open the registry %s\%s: %ldInvalid keyName in Util_CreateKey |