Windows Analysis Report
Setup.exe

Overview

General Information

Sample name: Setup.exe
Analysis ID: 1500187
MD5: cd31545772cdb4e84902f25d3363c58d
SHA1: 88ab168cbfc19785caab11109b4682d3cfcfafae
SHA256: 3c80fd894036f549fb831d271595df775ebaba7d98fdeea579bfae3c9d42ec53
Infos:

Detection

Score: 13
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Installs new ROOT certificates
Creates files inside the driver directory
Creates files inside the system directory
Creates or modifies windows services
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops certificate files (DER)
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
Queries the volume information (name, serial number etc) of a device
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Source: Setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\Setup.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore SRInitDone
Source: Setup.exe Static PE information: certificate valid
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData\Roaming
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{8c53135d-4d2b-fe49-94ed-d03bab0b35f4}\SETBE72.tmp Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{8c53135d-4d2b-fe49-94ed-d03bab0b35f4}
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\SysWOW64\SER9ab95.rra
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\SysWOW64\SERSaba5.rra
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\inf\SERSabb4.rra
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\inf\SERWabb4.rra
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\FileRepository\ser2pl.inf_amd64_f8875256a6be18aa
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\drvstore.tmp
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\inf\oem4.inf
Source: C:\Windows\System32\drvinst.exe File deleted: C:\Windows\System32\DriverStore\Temp\{8c53135d-4d2b-fe49-94ed-d03bab0b35f4}\SETBD77.tmp
Source: Setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: clean13.winEXE@6/36@0/0
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Program Files (x86)\InstallShield Installation Information\
Source: C:\Users\user\Desktop\Setup.exe Mutant created: \Sessions\1\BaseNamedObjects\ECC3713C-08A4-40E3-95F1-7D0704F1CE5E
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6372:120:WilError_03
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{1FEFAA11-8F3D-4F80-A5E1-443AA44B1895}\
Source: Setup.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Setup.exe File read: C:\Users\user\AppData\Local\Temp\{1FEFAA11-8F3D-4F80-A5E1-443AA44B1895}\Disk1\setup.ini
Source: C:\Users\user\Desktop\Setup.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\Setup.exe File read: C:\Users\user\Desktop\Setup.exe
Source: unknown Process created: C:\Users\user\Desktop\Setup.exe "C:\Users\user\Desktop\Setup.exe"
Source: C:\Users\user\Desktop\Setup.exe Process created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{361795EF-EBB0-40A6-AE64-94AAA21D87EF}
Source: C:\Users\user\Desktop\Setup.exe Process created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{361795EF-EBB0-40A6-AE64-94AAA21D87EF}
Source: unknown Process created: C:\Windows\System32\SrTasks.exe C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1
Source: C:\Windows\System32\SrTasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{254b0c33-77a9-5a4b-be66-7d93eedacb69}\ser2pl.inf" "9" "4b334f3bf" "0000000000000160" "WinSta0\Default" "0000000000000184" "208" "C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\VISTA"
Source: C:\Users\user\Desktop\Setup.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: acgenral.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: winmm.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: samcli.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: msacm32.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: urlmon.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: mpr.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: sspicli.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: iertutil.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: srvcli.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: netutils.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: lz32.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: propsys.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: profapi.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: riched32.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: riched20.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: usp10.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: msls31.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBEW64.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: sfc.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: sfc_os.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: srclient.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: spp.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: powrprof.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: vssapi.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: vsstrace.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: umpdc.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: sxproxy.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: devrtl.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: drvstore.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: spinf.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: spp.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srclient.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ktmw32.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: wer.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: bcd.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: dsrole.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: msxml3.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vss_ps.dll
Source: C:\Windows\System32\drvinst.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\drvinst.exe Section loaded: devrtl.dll
Source: C:\Windows\System32\drvinst.exe Section loaded: drvstore.dll
Source: C:\Windows\System32\drvinst.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\drvinst.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\drvinst.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\drvinst.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\drvinst.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\drvinst.exe Section loaded: gpapi.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: sfc.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: sfc_os.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: srclient.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: spp.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: powrprof.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: vssapi.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: vsstrace.dll
Source: C:\Users\user\Desktop\Setup.exe Section loaded: umpdc.dll
Source: C:\Users\user\Desktop\Setup.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
Source: C:\Users\user\Desktop\Setup.exe File written: C:\Users\user\AppData\Local\Temp\{1FEFAA11-8F3D-4F80-A5E1-443AA44B1895}\setup.ini
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Windows\SysWOW64\RICHED32.DLL
Source: Window Recorder Window detected: More than 3 window changes detected
Source: Setup.exe Static PE information: certificate valid
Source: Setup.exe Static file information: File size 3176304 > 1048576

Persistence and Installation Behavior

barindex
Source: C:\Windows\System32\drvinst.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 Blob
Source: C:\Windows\System32\drvinst.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 Blob
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{1FEFAA11-8F3D-4F80-A5E1-443AA44B1895}\_Setup.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{8c53135d-4d2b-fe49-94ed-d03bab0b35f4}\SETBD77.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Vista\ser2ac03.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\Temp\QRemabb4.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBE59db.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\Temp\Uninabe3.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\_IsR5a1a.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{1FEFAA11-8F3D-4F80-A5E1-443AA44B1895}\Disk1\setup.exe Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Setu598d.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\SysWOW64\SER9ab95.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\Temp\Deleabd4.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\dotn599d.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{1FEFAA11-8F3D-4F80-A5E1-443AA44B1895}\Disk1\ISSetup.dll Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\isrt59eb.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\SysWOW64\SERSaba5.rra Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{8c53135d-4d2b-fe49-94ed-d03bab0b35f4}\SETBD77.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\Temp\QRemabb4.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\Temp\Uninabe3.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\SysWOW64\SER9ab95.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\Temp\Deleabd4.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\SysWOW64\SERSaba5.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\_IsR5a1a.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Setu598d.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\dotn599d.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\ISBE59db.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\isrt59eb.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\SysWOW64\SERSaba5.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\Temp\QRemabb4.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\Temp\Deleabd4.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\Temp\Uninabe3.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Vista\ser2ac03.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe File created: C:\Windows\SysWOW64\SER9ab95.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Registry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Source: C:\Windows\System32\SrTasks.exe Registry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{1FEFAA11-8F3D-4F80-A5E1-443AA44B1895}\_Setup.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{8c53135d-4d2b-fe49-94ed-d03bab0b35f4}\SETBD77.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Vista\ser2ac03.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Windows\Temp\QRemabb4.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Windows\Temp\Uninabe3.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\_IsR5a1a.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{1FEFAA11-8F3D-4F80-A5E1-443AA44B1895}\Disk1\setup.exe Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Setu598d.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\SER9ab95.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Windows\Temp\Deleabd4.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\dotn599d.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{5D8075F0-4DED-4B0C-B9EB-DF1DCD69C020}\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\isrt59eb.rra Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{1FEFAA11-8F3D-4F80-A5E1-443AA44B1895}\Disk1\ISSetup.dll Jump to dropped file
Source: C:\Users\user\Desktop\Setup.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\SERSaba5.rra Jump to dropped file
Source: C:\Windows\System32\SrTasks.exe TID: 6360 Thread sleep time: -300000s >= -30000s
Source: C:\Users\user\Desktop\Setup.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Setup.exe File Volume queried: C:\Windows FullSizeInformation
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData\Roaming
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft
Source: C:\Users\user\Desktop\Setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
Source: unknown Process created: C:\Windows\System32\drvinst.exe drvinst.exe "4" "0" "c:\users\user\appdata\local\temp\{254b0c33-77a9-5a4b-be66-7d93eedacb69}\ser2pl.inf" "9" "4b334f3bf" "0000000000000160" "winsta0\default" "0000000000000184" "208" "c:\users\user\appdata\local\temp\{5d8075f0-4ded-4b0c-b9eb-df1dcd69c020}\{ecc3713c-08a4-40e3-95f1-7d0704f1ce5e}\vista"
Source: C:\Windows\System32\drvinst.exe Queries volume information: C:\Windows\System32\DriverStore\Temp\{8c53135d-4d2b-fe49-94ed-d03bab0b35f4}\ser2pl.cat VolumeInformation
Source: C:\Windows\System32\drvinst.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
⊘No contacted IP infos