Click to jump to signature section
Source: | Binary string: d:\a01\_work\2\s\\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.2.dr |
Source: | Binary string: C:\ReleaseAI\win\Release\custact\x86\AICustAct.pdb source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr, MSI421B.tmp.2.dr |
Source: | Binary string: D:\build\ob\bora-20089737\bora\build\build\vmnat\release\win32\vmnat.pdb source: APLICA O SEGURA.exe, 00000006.00000000.1370178372.00000000008D0000.00000002.00000001.01000000.00000004.sdmp, APLICA O SEGURA.exe.2.dr |
Source: C:\Windows\System32\msiexec.exe | File opened: z: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: x: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: v: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: t: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: r: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: p: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: n: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: l: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: j: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: h: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: f: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: b: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: y: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: w: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: u: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: s: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: q: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: o: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: m: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: k: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: i: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: g: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: e: | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | File opened: c: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: a: | Jump to behavior |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0 |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: id-Processo_Z5TGVQUK.msi, APLICA O SEGURA.exe.2.dr, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: id-Processo_Z5TGVQUK.msi, APLICA O SEGURA.exe.2.dr, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: id-Processo_Z5TGVQUK.msi, APLICA O SEGURA.exe.2.dr, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: id-Processo_Z5TGVQUK.msi, APLICA O SEGURA.exe.2.dr, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: id-Processo_Z5TGVQUK.msi, APLICA O SEGURA.exe.2.dr, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: APLICA O SEGURA.exe.2.dr, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://crl3.digicert.com/assured-cs-g1.crl00 |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://crl4.digicert.com/assured-cs-g1.crl0L |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://ocsp.digicert.com0 |
Source: id-Processo_Z5TGVQUK.msi, APLICA O SEGURA.exe.2.dr, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: id-Processo_Z5TGVQUK.msi, APLICA O SEGURA.exe.2.dr, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://ocsp.digicert.com0L |
Source: id-Processo_Z5TGVQUK.msi, APLICA O SEGURA.exe.2.dr, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://t1.symcb.com/ThawtePCA.crl0 |
Source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://t2.symcb.com0 |
Source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://tl.symcb.com/tl.crl0 |
Source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://tl.symcb.com/tl.crt0 |
Source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: http://tl.symcd.com0& |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0 |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://www.vmware.com/0 |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: http://www.vmware.com/0/ |
Source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: https://www.advancedinstaller.com |
Source: APLICA O SEGURA.exe.2.dr | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: https://www.thawte.com/cps0/ |
Source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr | String found in binary or memory: https://www.thawte.com/repository0W |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Section loaded: security.dll | Jump to behavior |
Source: id-Processo_Z5TGVQUK.msi | ReversingLabs: Detection: 14% |
Source: id-Processo_Z5TGVQUK.msi | Virustotal: Detection: 11% |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\id-Processo_Z5TGVQUK.msi" | |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 405A35FE4080A1D43DBAF24C899E36CF | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 405A35FE4080A1D43DBAF24C899E36CF | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Jump to behavior |
Source: | Binary string: d:\a01\_work\2\s\\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.2.dr |
Source: | Binary string: C:\ReleaseAI\win\Release\custact\x86\AICustAct.pdb source: id-Processo_Z5TGVQUK.msi, MSI447D.tmp.2.dr, MSI4579.tmp.2.dr, MSI450B.tmp.2.dr, MSI421B.tmp.2.dr |
Source: | Binary string: D:\build\ob\bora-20089737\bora\build\build\vmnat\release\win32\vmnat.pdb source: APLICA O SEGURA.exe, 00000006.00000000.1370178372.00000000008D0000.00000002.00000001.01000000.00000004.sdmp, APLICA O SEGURA.exe.2.dr |
Source: shfolder.dll.2.dr | Static PE information: section name: .didata |
Source: shfolder.dll.2.dr | Static PE information: section name: .4rj |
Source: shfolder.dll.2.dr | Static PE information: section name: .sJZ |
Source: shfolder.dll.2.dr | Static PE information: section name: .X*u |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI450B.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI4579.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI447D.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI421B.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\shfolder.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\vcruntime140.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 2DC0005 value: E9 6B 22 12 74 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 76EE2270 value: E9 9A DD ED 8B | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 2DD0007 value: E9 DB AB 14 74 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 76F1ABE0 value: E9 2E 54 EB 8B | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 2DF0005 value: E9 6B 15 0B 74 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 76EA1570 value: E9 9A EA F4 8B | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 2E00008 value: E9 FB 90 0F 74 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 76EF9100 value: E9 10 6F F0 8B | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 31F0005 value: E9 4B BC 06 73 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 7625BC50 value: E9 BA 43 F9 8C | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 3200005 value: E9 8B F9 04 73 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 7624F990 value: E9 7A 06 FB 8C | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 3210005 value: E9 EB C2 A7 72 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 75C8C2F0 value: E9 1A 3D 58 8D | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 3230005 value: E9 3B C4 A6 72 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Memory written: PID: 3092 base: 75C9C440 value: E9 CA 3B 59 8D | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Special instruction interceptor: First address: 000000006CA8226F instructions rdtsc caused by: RDTSC with Trap Flag (TF) |
Source: C:\Users\user\AppData\Roaming\APLICA O SEGURA.exe | Special instruction interceptor: First address: 000000006C7F404D instructions rdtsc caused by: RDTSC with Trap Flag (TF) |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: APLICA O SEGURA.exe.2.dr | Binary or memory string: VMware |
Source: APLICA O SEGURA.exe.2.dr | Binary or memory string: VMnet8 |
Source: APLICA O SEGURA.exe.2.dr | Binary or memory string: acpiacpiGPEahciaioaioGenericaioHttpaioKernelaioMgraioWin32aioWin32CompletionamdIommuappstateassignHwasyncsocketatapiCdromauthenticodeautomationAVCapturebackdoorbarrierbatteryblitbrtalkbuslogicbuslogicMdevbuttoncdromcheckpointchecksumchipsetcmoscptOpscpucountCpuidInfocrc32crtboracuidataCachedataSetsMgrdataSetsStoredeviceGroupdevicePowerOndeviceSwapdeviceThreaddictdigestlibdirectBootdiskdisklibdiskVmnixdmadmgdnddockerduiduiDevicesduiLocalizationduiMKSduiProxyAppsdumperdvxe1000efinvefivarstoreehcienableDetTimerepdextcfgdevicefakeDmafiltlibFiltLibTestLogflashramfloppyfsresxftConfigftcptgmmgpumgmtgrainTrackgrmguestAppMonitorguestInstallguest_msgguest_rpcguestVarsguiguiWin32HeaphbaCommonhbrhdaudiohdaudio_alsahgfshgfsServerhidQueuehostctlhostonlyhpethttpich7minputdevtapipcipcMgrkeyboardkeymapkeypersistlargepagelibconnectlicensellclsilogiclwdFiltermacbwmacfimacfiltermachPollmaclatencymainmainMemmainMemReplayCheckmasReceiptmemoryHotplugmemspacemigratemigrateVMmirrormksmksBasicOpsmksClientmksControlmksCursorPositionmksDX11WindowmksDX11RenderermksDX11BasicmksDX11ResourceViewmksDX11ShimOpsmksFramemksGLBasicmksGLContextMuxmksGLDrawmksGLFBOmksGLManagermksGLQuerymksGLShadermksGLStatemksGLTextureViewmksGLWindowmksHostCursormksInputmksKeyboardmksMousemksMTLRenderermksRenderOpsmksServermksSWBmksVulkanRenderermksVulkanCmdsmksWinBSODmormstatmvncnamespaceDbnamespaceMgrnetPktnumanumaHostnvdimmnvmenvramMgrobjcobjliboemDeviceopNotificationopromovhdmemparallelpassthroughpcipcibridgepci_e1000pci_ehcipci_hdaudiopci_hyperpciPassthrupciPluginpci_scsipci_svgapci_uhcipci_videpci_vlancepci_vmcipci_vmxnet3pci_xhcipmemobjpollprecisionclockpromotediskpvnvrampvscsiqatremoteDevicereplayVMXsbxscsisecureBootserialserviceImplserviceUsersgsgxsgxmpasgxRegistrationToolshadersharedFolderMgrshim3DslotfssmbiossmcsmramsnapshotsoundsparseCheckersslstate3dstatssvgasvgadevtapsvga_rectsyncWaitQtarReadertimertoolstoolsIsotoolsversiontpm2emutpm2VerificationtxtudpfecuhciundopointunityMsgupitbeupitdusbusb_xhciutiluwtvaBasicOpsvcpuhotplugvcpuNUMAvdfsvdfs_9pvdpPluginvdtiPciCfgSpcvflashvgavideviewClientvigorviommuvlancevmcfvmcivmgencvmGLvmhsvmIPCvmkcfgvmkEventvmkmgmtlibvmLockvmmousevmnamevmnetBridgevmOvhdvmUpsellControllervmvavmWindowControllervmxnetvmxnet3vmxvmdbCallbacksvncBlitvncDecodevncEncodevncServervncServerOSvnetvprobeVProbeClientvrdmavsanobjvsockvsockProxyvthreadvtpmvuivusbaudiovusbccidvusbhidvusbkeyboardvusbmousevusbrngvusbtabletvusbvideovvolbevvtdvwdtwifiwin32utilworkerxpm |