Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
EasyLogUSB+Installer.exe

Overview

General Information

Sample name:EasyLogUSB+Installer.exe
Analysis ID:1501387
MD5:d3d4273692e34102b88c513ad1c10040
SHA1:1b75e5c2644fbf075040df437b15d4d2c128c2cf
SHA256:cc2652dc33020fab609750a6f627e2f8e6597960b25f210981e62f5ad92f7d70
Infos:

Detection

Score:6
Range:0 - 100
Whitelisted:false
Confidence:40%

Compliance

Score:45
Range:0 - 100

Signatures

Checks for available system drives (often done to infect USB drives)
Creates driver files
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Launches processes in debugging mode, may be used to hinder debugging
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious Execution From GUID Like Folder Names
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

  • System is w10x64_ra
  • EasyLogUSB+Installer.exe (PID: 7056 cmdline: "C:\Users\user\Desktop\EasyLogUSB+Installer.exe" MD5: D3D4273692E34102B88C513AD1C10040)
    • msiexec.exe (PID: 6372 cmdline: "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{0D022C78-2169-466B-A31C-8D092A6A94A4}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe" MD5: 9D09DC1EDA745A5F87553048E57620CF)
  • msiexec.exe (PID: 6328 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 6204 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 7728979BC62DF75D3D4A0D670E15253D C MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 5708 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 8679B04C71729C7D188454F6AA437A24 MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • EL-USB Driver Setup.exe (PID: 1548 cmdline: "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe" MD5: 4BD3D58BEB869D0895D93ACCADC08032)
  • cleanup
No yara matches
Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{0D022C78-2169-466B-A31C-8D092A6A94A4}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe", CommandLine: "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{0D022C78-2169-466B-A31C-8D092A6A94A4}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\msiexec.exe, NewProcessName: C:\Windows\SysWOW64\msiexec.exe, OriginalFileName: C:\Windows\SysWOW64\msiexec.exe, ParentCommandLine: "C:\Users\user\Desktop\EasyLogUSB+Installer.exe", ParentImage: C:\Users\user\Desktop\EasyLogUSB+Installer.exe, ParentProcessId: 7056, ParentProcessName: EasyLogUSB+Installer.exe, ProcessCommandLine: "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{0D022C78-2169-466B-A31C-8D092A6A94A4}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe", ProcessId: 6372, ProcessName: msiexec.exe
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Compliance

barindex
Source: EasyLogUSB+Installer.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: EasyLogUSB+Installer.exeStatic PE information: certificate valid
Source: C:\Windows\System32\msiexec.exeFile opened: z:
Source: C:\Windows\System32\msiexec.exeFile opened: x:
Source: C:\Windows\System32\msiexec.exeFile opened: v:
Source: C:\Windows\System32\msiexec.exeFile opened: t:
Source: C:\Windows\System32\msiexec.exeFile opened: r:
Source: C:\Windows\System32\msiexec.exeFile opened: p:
Source: C:\Windows\System32\msiexec.exeFile opened: n:
Source: C:\Windows\System32\msiexec.exeFile opened: l:
Source: C:\Windows\System32\msiexec.exeFile opened: j:
Source: C:\Windows\System32\msiexec.exeFile opened: h:
Source: C:\Windows\System32\msiexec.exeFile opened: f:
Source: C:\Windows\System32\msiexec.exeFile opened: b:
Source: C:\Windows\System32\msiexec.exeFile opened: y:
Source: C:\Windows\System32\msiexec.exeFile opened: w:
Source: C:\Windows\System32\msiexec.exeFile opened: u:
Source: C:\Windows\System32\msiexec.exeFile opened: s:
Source: C:\Windows\System32\msiexec.exeFile opened: q:
Source: C:\Windows\System32\msiexec.exeFile opened: o:
Source: C:\Windows\System32\msiexec.exeFile opened: m:
Source: C:\Windows\System32\msiexec.exeFile opened: k:
Source: C:\Windows\System32\msiexec.exeFile opened: i:
Source: C:\Windows\System32\msiexec.exeFile opened: g:
Source: C:\Windows\System32\msiexec.exeFile opened: e:
Source: C:\Windows\System32\msiexec.exeFile opened: c:
Source: C:\Windows\System32\msiexec.exeFile opened: a:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x86\SiLib.sys
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3a61ad.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI647C.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6539.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\SiUSBXp.dll
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3a61af.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3a61af.msi
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSI647C.tmp
Source: EasyLogUSB+Installer.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: clean6.winEXE@10/45@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\Public\Desktop\EasyLog USB.lnk
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile created: C:\Users\user\AppData\Local\Temp\{0D022C78-2169-466B-A31C-8D092A6A94A4}\
Source: EasyLogUSB+Installer.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile read: C:\Users\user\AppData\Local\Temp\{0D022C78-2169-466B-A31C-8D092A6A94A4}\Setup.INI
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile read: C:\Users\user\Desktop\EasyLogUSB+Installer.exe
Source: unknownProcess created: C:\Users\user\Desktop\EasyLogUSB+Installer.exe "C:\Users\user\Desktop\EasyLogUSB+Installer.exe"
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{0D022C78-2169-466B-A31C-8D092A6A94A4}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 7728979BC62DF75D3D4A0D670E15253D C
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 8679B04C71729C7D188454F6AA437A24
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe"
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{0D022C78-2169-466B-A31C-8D092A6A94A4}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe"
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 7728979BC62DF75D3D4A0D670E15253D C
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 8679B04C71729C7D188454F6AA437A24
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe"
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: apphelp.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: msi.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: textinputframework.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: textshaping.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: srpapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textinputframework.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textshaping.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wkscli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: cryptsp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: rsaenh.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: cryptbase.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msisip.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: gpapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msihnd.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: dwmapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: pcacli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: oleacc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windowscodecs.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: riched20.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: usp10.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msls31.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: linkinfo.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntshrui.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: srvcli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cscapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: acgenral.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: uxtheme.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: winmm.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: samcli.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: msacm32.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: version.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: dwmapi.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: urlmon.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: mpr.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: sspicli.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: winmmbase.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: winmmbase.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: iertutil.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: srvcli.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: aclayers.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: sfc.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: sfc_os.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: textinputframework.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: coremessaging.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: coremessaging.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: textshaping.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile written: C:\Users\user\AppData\Local\Temp\{0D022C78-2169-466B-A31C-8D092A6A94A4}\Setup.INI
Source: EasyLogUSB+Installer.exeStatic PE information: certificate valid
Source: EasyLogUSB+Installer.exeStatic file information: File size 19500624 > 1048576
Source: EasyLogUSB+Installer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\ExportToExcel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\EasyLog USB.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\SiUSBXp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI647C.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exeJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\MSI478F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x86\SiLib.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x64\SiUSBXp.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x86\SiUSBXp.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\EasyLogGraph.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x64\SiLib.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\CustomControls.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\WPFToolkit.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\SiUSBXp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI647C.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyLog USB
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyLog USB\EasyLog USB.lnk
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyLog USB\EasyLogGraph.lnk
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\ExportToExcel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\EasyLog USB.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\SiUSBXp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI647C.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exeJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI478F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x86\SiLib.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x64\SiUSBXp.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x86\SiUSBXp.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\EasyLogGraph.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x64\SiLib.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\CustomControls.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\WPFToolkit.dllJump to dropped file
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile Volume queried: C:\Users\user\AppData\Local\Temp FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformation
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe"
Source: C:\Windows\SysWOW64\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
Windows Service
1
Windows Service
22
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Process Injection
1
Disable or Modify Tools
LSASS Memory11
Peripheral Device Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
1
Process Injection
Security Account Manager2
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
NTDS12
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
File Deletion
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
EasyLogUSB+Installer.exe0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Program Files (x86)\EasyLog USB\CustomControls.dll0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\EasyLogGraph.exe0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\ExportToExcel.dll0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\WPFToolkit.dll0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\x64\SiLib.sys0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\x64\SiUSBXp.sys0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\x86\SiLib.sys0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\x86\SiUSBXp.sys0%ReversingLabs
C:\Users\user\AppData\Local\Temp\MSI478F.tmp0%ReversingLabs
C:\Windows\Installer\MSI647C.tmp0%ReversingLabs
C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exe0%ReversingLabs
C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exe0%ReversingLabs
C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exe0%ReversingLabs
C:\Windows\SysWOW64\SiUSBXp.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1501387
Start date and time:2024-08-29 20:47:16 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:20
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
Analysis Mode:stream
Analysis stop reason:Timeout
Sample name:EasyLogUSB+Installer.exe
Detection:CLEAN
Classification:clean6.winEXE@10/45@0/0
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
  • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, login.live.com, settings-win.data.microsoft.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
  • VT rate limit hit for: EasyLogUSB+Installer.exe
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:modified
Size (bytes):14060
Entropy (8bit):5.731046015041822
Encrypted:false
SSDEEP:
MD5:38C8EFB5F66D923D228E69BA8B8F6D12
SHA1:4916C3E27FEA40547FE6D94E0F092E4269F29C1C
SHA-256:771AE6B0FB5CBB29D017DB86522025C1BFA3541860E1CC8FD4E731C916ADA19E
SHA-512:5468CFFD6522CBAE57C6B6E65DE8E85D9FE013386BA28832EFCC4539F1565AD4383E5D88C31C59A9BE7DF9A1D87F71C9B8D7465C38BA7BF9E953412EDCF22247
Malicious:false
Reputation:unknown
Preview:...@IXOS.@.....@.v.Y.@.....@.....@.....@.....@.....@......&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}..EasyLog USB..EasyLog USB.msi.@.....@.....@.....@......ARPPRODUCTICON.exe..&.{8C7E2C80-4C6F-4A5C-9FDD-5AA316A9E29A}.....@.....@.....@.....@.......@.....@.....@.......@......EasyLog USB......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{429FE619-EEB7-4E48-AF7A-4F56DD1C7491}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{1D213698-CDE4-4051-B5BD-2BBDFE318583}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{B2ECCF77-395E-4A26-A4BF-5EC89425F03F}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{AFECBE12-FD2C-45CC-80F8-C71798C38400}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{A058DD12-721A-4A06-81C5-933F86CBD9A8}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{C7CB0A68-EC59-41D8-B200-84E9EA2E80DD}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{782F7E0F-9847-4B86-B5B0-33A2239F1B52}&
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):83968
Entropy (8bit):6.294061771215002
Encrypted:false
SSDEEP:
MD5:D45DC6705A858837B48002B099259447
SHA1:7381790B9470B8120D40CC8170EF31625AFA41FC
SHA-256:625364E42240CCD4D34DCEDDDA385C5B999C82254866886FDECF71E2E51EAA82
SHA-512:BBD23EBB9C171F599FCD7FBFBCC4074364A892402A40BBA1F501C1E6EFF9803B239F5C46D834D5C19D00630DA5C87D3BB4633E09871685FE25981815918EAD6C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....N............" ..0..@..........r_... ...`....... ....................................`................................. _..O....`..............................l^..8............................................ ............... ..H............text...x?... ...@.................. ..`.rsrc........`.......B..............@..@.reloc...............F..............@..B................T_......H...........dl..............xm..........................................6.(.....(....*..,..{.......+..,..{....o......(....*2.s....}....*"..(....*"..(....*...0..C.......s ...%....s!...o"...%..o#...%..o$...%(i...o%.....(&....o'....o(...*..{....*:..}.....()...*..{....*:..}.....()...*..{....*:..}.....()...*..{....*:..}.....()...*..{....*:..}.....()...*..{....*:..}.....()...*....0...........(*....(........(+.... . ...(+.... .....(+..........(,...}......O.O.O(,...}......O.O.O(,...}
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):636816
Entropy (8bit):6.215505980302389
Encrypted:false
SSDEEP:
MD5:4BD3D58BEB869D0895D93ACCADC08032
SHA1:9005888DFBC0B2483DC4DA69683B46AA70A54283
SHA-256:604330AE230A4FDE9A3C4401CDD544394910D55DDF651A84259E0B03B39DF35E
SHA-512:6966206E8E3A038B3F142459E334C3D47AD67CAE95091EB1C022C5FE00BA14EF9EDBC0010AD9795E045CC6DEE63A81EFF262E0A7A8EF30373159BBFA25C9556B
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........j.:..ki..ki..ki3.4i..ki3.6i..ki...i..ki...ih.ki.(xi..ki..ji..ki...i..ki...i..ki...i..kiRich..ki........PE..L....HM.................p... ....................@.................................%......................................../..........................................................................@..................../..@....................text....f.......p.................. ..`.rdata..............................@..@.data....`...`...0...`..............@....rsrc...............................@..@........................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Windows setup INFormation
Category:dropped
Size (bytes):1774
Entropy (8bit):5.242834253911726
Encrypted:false
SSDEEP:
MD5:4AE3D4215836D424C461C60E841509A8
SHA1:155EFD4F098E9A5294AFF18E2A0E45AAC5ED0310
SHA-256:6737F7F6737B4E37004D3F3FE3DBC9A2DB68FB74DF481B39AA0ACDBD238EDA79
SHA-512:5CB6C95906B6DC23622FDE07C5A04554B90DA8DC74E87B8A42BB60ED5B7B0A47678FD241250144BB345FB61DFDE4E183DF2F3D9563C7C9DF08D6A1782F3E5C5A
Malicious:false
Reputation:unknown
Preview:; EasyLog USB Device Driver..; Silabs USBXpress, Copyright (c) 2010, Silicon Laboratories......[Version]..Signature=$WINDOWS NT$..Class=USB..ClassGUID={36fc9e60-c465-11cf-8056-444553540000}..Provider=%MFGNAME%..DriverVer=07/14/2009,3.3..CatalogFile=SiUSBXp.cat....[Manufacturer]..%MFGNAME%=DeviceList, NTamd64....[DestinationDirs]..DefaultDestDir=10..;System32\Drivers..DriverCopyFiles=10..,System32\Drivers....[SourceDisksNames.x86]..1=%INSTDISK%,,,....[SourceDisksFiles.x86]..SiUSBXp.sys=1,\x86..SiLib.sys=1,\x86....[SourceDisksNames.amd64]..1=%INSTDISK%,,,....[SourceDisksFiles.amd64]..SiUSBXp.sys=1,\x64..SiLib.sys=1,\x64....[DeviceList]..%DESCRIPTION%=DriverInstall,USB\VID_10C4&PID_0002....[DeviceList.NTamd64]..%DESCRIPTION%=DriverInstall,USB\VID_10C4&PID_0002....[ControlFlags]..ExcludeFromSelect=*....;------------------------------------------------------------------------------..; Windows 2000 Sections..;------------------------------------------------------------------------------....
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows HtmlHelp Data
Category:dropped
Size (bytes):11118090
Entropy (8bit):7.999336140233879
Encrypted:true
SSDEEP:
MD5:B40F9A166584B9979C4DDF94E9C58B84
SHA1:7A885114A83F0A73ADEAF1180FD8182BDE270678
SHA-256:A7B13BEB1F0EE9EB22CB72B41D4396B27834FCB8A0C98DFBB1DE7283C6DBF345
SHA-512:7D19BF6F1951759209DCD58B5EEDC813645E8F688117C09E2E09B987F6F8EBE7EB9CBD67D009AEA970BE99AFC72FF76C9F9AA7589CC35A91DD8DB41E364B81BF
Malicious:false
Reputation:unknown
Preview:ITSF....`.......^G!........|.{.......".....|.{......."..`...............x.......T.......................................ITSP....T...........................................j..].!......."..T...............PMGL................./..../#IDXHDR......../#ITBITS..../#IVB....A.../#STRINGS......}./#SYSTEM....../#TOPICS......P./#URLSTR....d.+./#URLTBL....h.|./$FIftiMain......../$OBJINST....U.?./$WWAssociativeLinks/..../$WWAssociativeLinks/Property....Q../$WWKeywordLinks/..../$WWKeywordLinks/Property....M../EasyLogUSB.hhc...../images/..../images/help_file_usb-v8.gif..Q..../index.htm....A./pdf/..../pdf/EL-GFX-1.pdf...T..../pdf/EL-GFX-2.pdf..d..q./pdf/EL-GFX-DTC.pdf..U..../pdf/EL-OEM-3.pdf.......#./pdf/EL-USB-1-LCD.pdf...3..4./pdf/EL-USB-1-PRO.pdf....g..../pdf/EL-USB-1-RCG.pdf....w..../pdf/EL-USB-1.pdf.......0./pdf/EL-USB-2+.pdf........./pdf/EL-USB-2-LCD+.pdf....~..../pdf/EL-USB-2-LCD.pdf....!..]./pdf/EL-USB-2.pdf........./pdf/EL-USB-3.pdf......~./pdf/EL-USB-4.pdf.......Z./pdf/EL-USB-5.pdf....s.
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):2468864
Entropy (8bit):7.154456571356211
Encrypted:false
SSDEEP:
MD5:3B858BC0334BA720B83C388E909ADB76
SHA1:D7E5D67093A04417127BCB78B3D429157E7D668B
SHA-256:19A191AAE469323D2BF25E1C7FB80BDD09E98F88BC4A6B3907BE12B57BE739AD
SHA-512:59375F6F2E2FAC2B4E226C850C37E03985399C99EF9FBEBDA953528723B62577E5E9BA8F74E5284B1CDFC90D7B5DC52D43B265DE05A4337A2952D30FDA6B9431
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......`..............0..L%..^.......j%.. ....%...@.. ........................&...........`.................................tj%.O.....%.LZ....................%.....<i%.............................................. ............... ..H............text....K%.. ...L%................. ..`.rsrc...LZ....%..\...N%.............@..@.reloc........%.......%.............@..B.................j%.....H...........8.......x...D.................................................(.........(.......(....}......(....}....*..0............(.....+..**...(.....*..0............{.....+..*&...}....*...0............(.....+..**...(.....*..0............{.....+..*&...}....*...0............(........( .......(!....#Y..#..("....(#.......,...o$...s%.....o&...s%........+...{....s%.....{....s%..........o'....o(...."...."...@o).....(.....o*.....o+.....o,....**...(-....*..0............}.....#......g
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):12519936
Entropy (8bit):5.976511471374955
Encrypted:false
SSDEEP:
MD5:99A338CA1E3B2F789BEBF09E5DA98DB6
SHA1:BF360B9A4A311350FF65EA63D18ED8823F9299F0
SHA-256:27767F40E341717951DCDF231C09ADFB0C85A411A541DEB59A18EC773D09D800
SHA-512:3A14BE46C94A4A2779FC8FF1C9E468A87C2D1981B0EB2461553B6B46A2D69C6D05540BF4874002D71288991708521D9ED91065F562575C49600042A82F812ECA
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...q./`..............0.................. ... ....@.. .......................`............`.................................0...O.... .......................@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B................d.......H........8.. ............0..P...........................................0............ 4......("....+..*.0.................o#....+..*B.........o$....*...0..1.........o%...r...p $...........%...%....o&...t.....+..*.....o'....*".((....*>..s....%.}....*...0..U..............,D..(...+.......,.....o)....o*...o+.....(...+...o,....o-...t!.......+....+...*....0..O.........o,....o-...t...........,...o.......o/....o0...o1.....o,....o-...t........+..*..0..o.................(2......+I...(
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):1656320
Entropy (8bit):6.478623936096293
Encrypted:false
SSDEEP:
MD5:7DBCED1DFC2BA8632169292C78DB9023
SHA1:C7902951A4853BDFA7074261F0C5444CF6137845
SHA-256:615536B9FBF5B1F79C081224D136EC6AD2DB6B51B73BC455F2D7F2F18A0F9C19
SHA-512:FD1E297513F66633DA1A7E61C3584A84E86144C7D1AECBE9FC3CF3CDECDAC20EA6D49E0E3C0F092B48026BA1E5FD94490896B9C045E2055415CB14380819567A
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N[-U/5~U/5~U/5~\W.~Y/5~\W.~v/5~U/4~.-5~:Y.~~/5~:Y.~./5~:Y.~'.5~:Y.~Q/5~:Y.~T/5~:Y.~T/5~:Y.~T/5~RichU/5~................PE..L....{qO...........!.........N......-................................................................................6..p.......T.... ..$E...................p.....................................`...@............................................text............................... ..`.rdata...'.......(..................@..@.data........@...\... ..............@....rsrc...$E... ...F...|..............@..@.reloc..B....p......................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):12278
Entropy (8bit):3.757781663348975
Encrypted:false
SSDEEP:
MD5:8506D085E11D902F8A1823E7E321BBDE
SHA1:ADBAD1E5A097730E6B887D813962AC725DAB4231
SHA-256:791BE0332C3BDCC86842EA3C144CF37E00192F0A318EDBC57A020979CF229417
SHA-512:E6E3050B4ABAC5E2BADBA0094E3D2712D315FB30E2B746ABFC41E0F864B6EDA675BBD92D26C21DF1F79D2DA5D2122AAE71522560B890E89B4C88CE8E05E3D3B9
Malicious:false
Reputation:unknown
Preview:Room 1 CO,Time,CO(ppm),Warning Level,Serial Number,Sensor Life Expiry,Overrange Exposure..1,15/03/2006 16:00:00,0.0,25.0,000000123,06/02/2011,No..2,15/03/2006 16:00:10,0.0,25.0..3,15/03/2006 16:00:20,0.0,25.0..4,15/03/2006 16:00:30,0.0,25.0..5,15/03/2006 16:00:40,0.0,25.0..6,15/03/2006 16:00:50,0.0,25.0..7,15/03/2006 16:01:00,5.0,25.0..8,15/03/2006 16:01:10,3.0,25.0..9,15/03/2006 16:01:20,0.0,25.0..10,15/03/2006 16:01:30,3.5,25.0..11,15/03/2006 16:01:40,4.0,25.0..12,15/03/2006 16:01:50,0.0,25.0..13,15/03/2006 16:02:00,0.0,25.0..14,15/03/2006 16:02:10,0.0,25.0..15,15/03/2006 16:02:20,0.0,25.0..16,15/03/2006 16:02:30,3.5,25.0..17,15/03/2006 16:02:40,3.0,25.0..18,15/03/2006 16:02:50,0.0,25.0..19,15/03/2006 16:03:00,0.0,25.0..20,15/03/2006 16:03:10,3.5,25.0..21,15/03/2006 16:03:20,0.0,25.0..22,15/03/2006 16:03:30,3.0,25.0..23,15/03/2006 16:03:40,0.0,25.0..24,15/03/2006 16:03:50,0.0,25.0..25,15/03/2006 16:04:00,0.0,25.0..26,15/03/2006 16:04:10,4.0,25.0..27,15/03/2006 16:04:20,4.5,25.0..28,1
Process:C:\Windows\System32\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):9484
Entropy (8bit):3.8494259019457355
Encrypted:false
SSDEEP:
MD5:B293E1467C132E759298BC9C6D6DED7D
SHA1:38326172C6A6146F0BF0F12A18144A1C38B379C6
SHA-256:4B0F35D8B010E8BFC24942AF1635DD6FDF8432AE5DD8B88D361EB1DF1AE06DD3
SHA-512:4D44BA05D56718B6AF663D0305B6646F0F7A8181BAD066C6C82D68F8608E4366B8F931F32E4B3DBE74D7747F6CADE5CA3B1099AE10B1CF8E233F79FFA44B76FF
Malicious:false
Reputation:unknown
Preview:EasyLog USB,Time,Current(%),High Alarm,Low Alarm,Serial Number..1,31/03/2005 16:35:00,14.2,80.0,20.0,987654322..2,31/03/2005 16:35:01,22.0,80.0,20.0..3,31/03/2005 16:35:02,28.2,80.0,20.0..4,31/03/2005 16:35:03,34.4,80.0,20.0..5,31/03/2005 16:35:04,39.2,80.0,20.0..6,31/03/2005 16:35:05,42.8,80.0,20.0..7,31/03/2005 16:35:06,46.0,80.0,20.0..8,31/03/2005 16:35:07,48.6,80.0,20.0..9,31/03/2005 16:35:08,50.6,80.0,20.0..10,31/03/2005 16:35:09,53.6,80.0,20.0..11,31/03/2005 16:35:10,55.6,80.0,20.0..12,31/03/2005 16:35:11,56.6,80.0,20.0..13,31/03/2005 16:35:12,58.2,80.0,20.0..14,31/03/2005 16:35:13,59.0,80.0,20.0..15,31/03/2005 16:35:14,59.6,80.0,20.0..16,31/03/2005 16:35:15,60.2,80.0,20.0..17,31/03/2005 16:35:16,60.8,80.0,20.0..18,31/03/2005 16:35:17,61.2,80.0,20.0..19,31/03/2005 16:35:18,61.6,80.0,20.0..20,31/03/2005 16:35:19,62.0,80.0,20.0..21,31/03/2005 16:35:20,62.4,80.0,20.0..22,31/03/2005 16:35:21,62.8,80.0,20.0..23,31/03/2005 16:35:22,63.2,80.0,20.0..24,31/03/2005 16:35:23,63.6,80.0,20.0.
Process:C:\Windows\System32\msiexec.exe
File Type:ISO-8859 text, with CRLF line terminators
Category:dropped
Size (bytes):15477
Entropy (8bit):3.633119065723989
Encrypted:false
SSDEEP:
MD5:489A922F2345B000FD6D82CD4217F1D5
SHA1:3DEF20F03E42CD21F273D5031BC4CE2C79716675
SHA-256:0AC3BFFE44A6FF29323208F95D6487F84F8FE172065AE5C37714E46C2690BFE1
SHA-512:1B655780BDDAB2AD1312F5BC10683A15312ED06E7288A702EB1BCE7ACAB94269D197929718EF99C8AB6BC154403087DA549B08A49637211163CBB7888459C216
Malicious:false
Reputation:unknown
Preview:EasyLog USB,Time,Celsius(.C),High Alarm,Low Alarm,Serial Number..1,24/03/2006 15:00:00,20,18,4,987654321..2,24/03/2006 15:30:00,20,18,4..3,24/03/2006 16:00:00,20,18,4..4,24/03/2006 16:30:00,19,18,4..5,24/03/2006 17:00:00,19,18,4..6,24/03/2006 17:30:00,23,18,4..7,24/03/2006 18:00:00,25,18,4..8,24/03/2006 18:30:00,15,18,4..9,24/03/2006 19:00:00,18,18,4..10,24/03/2006 19:30:00,19,18,4..11,24/03/2006 20:00:00,18,18,4..12,24/03/2006 20:30:00,16,18,4..13,24/03/2006 21:00:00,15,18,4..14,24/03/2006 21:30:00,13,18,4..15,24/03/2006 22:00:00,12,18,4..16,24/03/2006 22:30:00,11,18,4..17,24/03/2006 23:00:00,10,18,4..18,24/03/2006 23:30:00,9,18,4..19,25/03/2006 00:00:00,9,18,4..20,25/03/2006 00:30:00,8,18,4..21,25/03/2006 01:00:00,8,18,4..22,25/03/2006 01:30:00,8,18,4..23,25/03/2006 02:00:00,7,18,4..24,25/03/2006 02:30:00,7,18,4..25,25/03/2006 03:00:00,7,18,4..26,25/03/2006 03:30:00,7,18,4..27,25/03/2006 04:00:00,7,18,4..28,25/03/2006 04:30:00,7,18,4..29,25/03/2006 05:00:00,6,18,4..30,25/03/2006 05:3
Process:C:\Windows\System32\msiexec.exe
File Type:ISO-8859 text, with CRLF line terminators
Category:dropped
Size (bytes):44219
Entropy (8bit):3.527582608719269
Encrypted:false
SSDEEP:
MD5:F8F1C58AA92A4C8850F434A77FE4411A
SHA1:CCCADD7400963855821CD1A849D5A184B54591AF
SHA-256:4ED4C172605C504B5FDB6660DE03B708D4174814DD738FC8DA38B9C439BA7447
SHA-512:053416800239F53B64D9622C97BEEF1C50C85442FFC3A0C1DF5304AFE667AB43B3BDBC489F94F250E5D4D595C3F4A02835213F0B12653F468B64D95D94CDDFDF
Malicious:false
Reputation:unknown
Preview:Logger Name,Time,Celsius(.C),High Alarm,Low Alarm,Humidity(%rh),High Alarm rh,Low Alarm rh,dew point(.C),Serial Number..1,05/01/2005 12:30:00,24.5,50.0,5.0,38.0,80.0,20.0,9.3,987654321..2,05/01/2005 12:30:10,24.5,50.0,5.0,38.0,80.0,20.0,9.3..3,05/01/2005 12:30:20,24.5,50.0,5.0,37.0,80.0,20.0,8.9..4,05/01/2005 12:30:30,24.5,50.0,5.0,37.0,80.0,20.0,8.9..5,05/01/2005 12:30:40,24.5,50.0,5.0,37.0,80.0,20.0,8.9..6,05/01/2005 12:30:50,24.5,50.0,5.0,37.0,80.0,20.0,8.9..7,05/01/2005 12:31:00,24.5,50.0,5.0,37.0,80.0,20.0,8.9..8,05/01/2005 12:31:10,24.5,50.0,5.0,37.0,80.0,20.0,8.9..9,05/01/2005 12:31:20,24.5,50.0,5.0,37.0,80.0,20.0,8.9..10,05/01/2005 12:31:30,24.5,50.0,5.0,36.5,80.0,20.0,8.7..11,05/01/2005 12:31:40,24.5,50.0,5.0,36.5,80.0,20.0,8.7..12,05/01/2005 12:31:50,24.5,50.0,5.0,36.5,80.0,20.0,8.7..13,05/01/2005 12:32:00,24.5,50.0,5.0,36.5,80.0,20.0,8.7..14,05/01/2005 12:32:10,25.0,50.0,5.0,36.5,80.0,20.0,9.1..15,05/01/2005 12:32:20,25.0,50.0,5.0,36.5,80.0,20.0,9.1..16,05/01/2005 12:32:30,2
Process:C:\Windows\System32\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):125852
Entropy (8bit):3.6068372981211265
Encrypted:false
SSDEEP:
MD5:E5477135B40BAFC5CDBC0887E9F43E91
SHA1:4A98CBD1BF41A7BDB4BABB53085131072914C832
SHA-256:ACCD81ED3E1A0DE10AB90D303C50B35185FFFBAC3ADB65675B22F923551D5792
SHA-512:E9BE123D171F9A5B5AD5E71CEC9457B7DB6B8B4B3AC253BBCE56973E14FE293EBCFF0A685D3D6786575716EFA27EB8CF70CD19DB2CD074A54884EFE248A9BC21
Malicious:false
Reputation:unknown
Preview:EasyLogUSB,Time,Celsius,Low Alarm,Serial Number..1,13/02/2004 22:30:00,20.5,10.0,987654321..2,13/02/2004 22:31:00,21.0,10.0..3,13/02/2004 22:32:00,21.5,10.0..4,13/02/2004 22:33:00,21.5,10.0..5,13/02/2004 22:34:00,21.0,10.0..6,13/02/2004 22:35:00,20.5,10.0..7,13/02/2004 22:36:00,20.0,10.0..8,13/02/2004 22:37:00,20.0,10.0..9,13/02/2004 22:38:00,19.5,10.0..10,13/02/2004 22:39:00,19.5,10.0..11,13/02/2004 22:40:00,19.5,10.0..12,13/02/2004 22:41:00,19.0,10.0..13,13/02/2004 22:42:00,19.0,10.0..14,13/02/2004 22:43:00,19.0,10.0..15,13/02/2004 22:44:00,19.0,10.0..16,13/02/2004 22:45:00,18.5,10.0..17,13/02/2004 22:46:00,18.5,10.0..18,13/02/2004 22:47:00,18.5,10.0..19,13/02/2004 22:48:00,18.5,10.0..20,13/02/2004 22:49:00,18.5,10.0..21,13/02/2004 22:50:00,18.5,10.0..22,13/02/2004 22:51:00,18.5,10.0..23,13/02/2004 22:52:00,18.0,10.0..24,13/02/2004 22:53:00,18.0,10.0..25,13/02/2004 22:54:00,18.0,10.0..26,13/02/2004 22:55:00,18.0,10.0..27,13/02/2004 22:56:00,18.0,10.0..28,13/02/2004 22:57:00,18.0,10.0
Process:C:\Windows\System32\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):8679
Entropy (8bit):3.717253632972772
Encrypted:false
SSDEEP:
MD5:86086555543DDAF5B4703A617984C70C
SHA1:CD3921237802C1958A888D0273519A6B6E3C3AD1
SHA-256:8A10FFA4AEDBDA127188FBC46437A04DE0618F3E056C084A76017990EB559C3F
SHA-512:011DE120A8EEDAF8A569567CBBBE6EA1D73AB7F30A6FF45B59735657107ED454EC7598A5C7B69A0E7C50E7CC246D8DC90F6D5AB615E19BD67EE27E2D77EC82D7
Malicious:false
Reputation:unknown
Preview:EasyLog USB,Time,Voltage(Volts),High Alarm,Low Alarm,Serial Number..1,31/03/2005 10:20:00,24.45,17.50,2.50,987654322..2,31/03/2005 10:20:01,24.05,17.50,2.50..3,31/03/2005 10:20:02,23.65,17.50,2.50..4,31/03/2005 10:20:03,23.30,17.50,2.50..5,31/03/2005 10:20:04,22.90,17.50,2.50..6,31/03/2005 10:20:05,22.55,17.50,2.50..7,31/03/2005 10:20:06,22.20,17.50,2.50..8,31/03/2005 10:20:07,21.85,17.50,2.50..9,31/03/2005 10:20:08,21.55,17.50,2.50..10,31/03/2005 10:20:09,21.20,17.50,2.50..11,31/03/2005 10:20:10,20.90,17.50,2.50..12,31/03/2005 10:20:11,20.55,17.50,2.50..13,31/03/2005 10:20:12,20.25,17.50,2.50..14,31/03/2005 10:20:13,19.95,17.50,2.50..15,31/03/2005 10:20:14,19.65,17.50,2.50..16,31/03/2005 10:20:15,19.35,17.50,2.50..17,31/03/2005 10:20:16,19.05,17.50,2.50..18,31/03/2005 10:20:17,18.80,17.50,2.50..19,31/03/2005 10:20:18,18.50,17.50,2.50..20,31/03/2005 10:20:19,18.20,17.50,2.50..21,31/03/2005 10:20:20,17.95,17.50,2.50..22,31/03/2005 10:20:21,17.70,17.50,2.50..23,31/03/2005 10:20:22,17.40,
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):467288
Entropy (8bit):6.047761304423497
Encrypted:false
SSDEEP:
MD5:195ED09E0B4F3B09EA4A3B67A0D3F396
SHA1:01A250631397C93C4AAB9A777A86E39FD8D84F09
SHA-256:AEF9FCBB874FC82E151E32279330061F8F22A77C05F583A0CB5E5696654AC456
SHA-512:B801C03EFA3E8079366A7782D2634A3686D88F64C3C31A03AA5CE71B7BF472766724D209290C231D55DA89DD4F03BD1C0153FFEB514E1D5D408CC2C713CD4098
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!................> ... ...@....@.. ...............................>....@.....................................S....@..................X....`......h................................................ ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ ......H..........|q..........8.......P .......................................LO.K. 6}.5N..LA..D..|..=T.+.%.O..!@....D.tLl.....8..o...x"...&..C.@"}.dd..CZ..+..4l|<.V....Z....=..)...':..n.....*.....K..{....*"..}....*F.~....(H...t<...*6.~.....(I...*.r...p.<...(J........(J...(K........*..(L...*F.~....oH...t....*6.~.....oI...*...0.."........u'.....,...(M...t......,...o....*...0..F........(....,.r...psN...z..(......o............sO...oP...........sO...oQ...*...0..F........(....-.
Process:C:\Windows\System32\msiexec.exe
File Type:Generic INItialization configuration [Driver Version]
Category:dropped
Size (bytes):483
Entropy (8bit):5.319487317274177
Encrypted:false
SSDEEP:
MD5:0A73FF24BBBB30B912BFC115A24019AB
SHA1:EE921F92A90C13A153094E090A93EEA572EA22A4
SHA-256:E19491ADE2529A48A75E625E512175ACD5BB98CA6739BEE958AAE5822E3CA488
SHA-512:9EAE1A0E046253EB041AB7020627F037A9D9B3C8853DCD09D8A7B9846ADEEC6B113772429992776E0FB732034470F76D7E481374CCAA45C97BFD045C816A10DE
Malicious:false
Reputation:unknown
Preview:[Driver Type]..USBXpress....[Driver Version]..3.3....[Product Name]..EasyLog USB Device....[Company Name]..Lascar Electronics Ltd.....[VID_PID List]..10C4_0002....[Install Subdirectories]..x86..x64....[Install Quiet Mode]..Off....[Uninstall Quiet Mode]..Off....[Copy Driver Files]..No....[XP_2K_2K3_VISTA INF Files]..EL-USB.inf....[XP_2K_2K3_VISTA Driver Files]...\x64\SiUSBXp.sys...\x64\SiLib.sys...\x86\SiUSBXp.sys...\x86\SiLib.sys....[XP_2K_2K3_VISTA Catalog Files]..siusbxp.cat..
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):8984
Entropy (8bit):6.928193234859025
Encrypted:false
SSDEEP:
MD5:0F98B187AC70FCBC464912A833656EB3
SHA1:3A9DA589492C7B9C419DA9BD0018100628F9D55E
SHA-256:5FED39B28E3E4BB08403553C508DCC5E242A99463A957BDF0C1E42F16E2A19D6
SHA-512:1B26CE1BDB28B8C1550C33D835AAD5DDBA9A190C525CA507A103926A5C7410DAE81EBD3CF8DF30C634B273A6926271E69BEA7BE539393D82286DD38391FC0592
Malicious:false
Reputation:unknown
Preview:0.#...*.H........#.0.#....1.0...+......0.....+.....7......0...0...+.....7.....[dd v.8N..6....5..101112175240Z0...+.....7.....0...0....R1.5.5.E.F.D.4.F.0.9.8.E.9.A.5.2.9.4.A.F.F.1.8.E.2.A.0.E.4.5.A.A.C.5.E.D.0.3.1.0...1..g08..+.....7...1*0(...F.i.l.e........e.l.-.u.s.b...i.n.f...0a..+.....7...1S0Q0,..+.....7........<.<.<.O.b.s.o.l.e.t.e.>.>.>0!0...+.........^.O...R...*.E.....0b..+.....7...1T0R.L.{.D.E.3.5.1.A.4.2.-.8.E.5.9.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0d..+.....7...1V0T...O.S.A.t.t.r.......>2.:.5...0.0.,.2.:.5...1.,.2.:.5...2.,.2.:.6...0.,.2.:.6...1...0....R1.8.A.8.0.D.E.0.C.F.D.5.2.1.0.E.9.A.3.2.5.C.7.2.B.1.2.4.0.B.4.4.2.F.B.4.F.4.2.2...1..q0:..+.....7...1,0*...F.i.l.e........s.i.u.s.b.x.p...s.y.s...0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0d..+.....7...1V0T...O.S.A.t.t.r.......>2.:.5...0.0.,.2.:.5...1.,.2.:.5...2.,.2.:.6...0.,.2.:.6...1...0i..+.....7...1[0Y04..+.....7...0&..... .....<.<.<.O.b.s.o.l.e.t.e
Process:C:\Windows\System32\msiexec.exe
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):24576
Entropy (8bit):5.444427923348303
Encrypted:false
SSDEEP:
MD5:971FA2980AB94A90B6A9A8385267E653
SHA1:FC739185177A85ED04B71C6A8D5FDFB72D919306
SHA-256:25E3D0517AFCBD70C1EBB53097F096E1BDA49DC4524E3C858489E5EC12825608
SHA-512:6D905EC5FCEE1F8ED2870AF0714A6C630DE3E8D8611406486ADDA08ECFC1873BD57932ED73F42EF93E4F49D40FCED13CA5C1C99795E8C0CECBBE6B56327E1337
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............uc.uc.uc.ub.uc.....uc.....uc....uc....uc.....uc....uc....uc....uc....uc.Rich.uc.................PE..d....?L.........."......B..........d................................................-..........................................................(.......0.......................8...@q...............................................p..@............................text....".......$.................. ..hpage.........@.......(.............. ..hinit.........`.......>.............. ..h.rdata.......p.......@..............@..H.data................D..............@....pdata...............H..............@..H.edata...............L..............@..@INIT....b............T.............. ....rsrc...0............Z..............@..B.reloc...............^..............@..B........................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):19456
Entropy (8bit):5.5838184446755195
Encrypted:false
SSDEEP:
MD5:CEDF7CFFCCD03451FD22DBAAC2E3DE8E
SHA1:3FD8383608DB769A1E2C8E0C1302C315DCA8B37E
SHA-256:A1F4B952099EBA4BA4E659782F85B45C4BBB411BF5B7C02D5BE0CC3DBF27AFF3
SHA-512:BBA0BF8C75E5A1B1AFC72F5B5A33CACA721DBB4589DE7B3430398AE147E2E2CF18A15932DF62D32423B1093453B55B48B9E99FB7549135E3CF33976229C47376
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......#d..g..g..g..n}w.e..g..B......b......e..n}g.d..n}q.f......f..n}n.b..n}p.f..n}u.f..Richg..........PE..d...A.?L.........."......:..........d...........................................................................................................P.......8...........................@a...............................................`..@............................text............................... ..hpage.........0...................... ..hinit....U....P.......6.............. ..h.rdata.......`.......8..............@..H.data...0....p.......>..............@....pdata...............@..............@..HINIT.................B.............. ....rsrc...8............H..............@..B................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):17408
Entropy (8bit):6.017219183396955
Encrypted:false
SSDEEP:
MD5:812318F3E7BD682E1C22F0B707F66E82
SHA1:AA17A293AEC2BF1239779A8D439F84B2602D76AD
SHA-256:9B4C47FAA4BD6F22E75CF8430BAC37E48108C35B6737850E583EFDC37C4D8A81
SHA-512:961BF96B873E269AD566B33243DF872D989AAB6EB51E29CC984D26BCCC331DDB60B45B301C2FD13D9F5E10BC26CAEFBD948D305D35EBAA22515453A3CD57CFD5
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................X...........!..L.!This program cannot be run in DOS mode....$.......................................................................................................................................................................................................................................................................................................................................................................................................>...z...z...z...z...J...#.......]#..{...]#..}...]#..{...]#..{...]#..{...Richz...........PE..L....?L.............................8.......-...............................D......................................1......D8..<....=..0....................A..4...P................................................-...............................text...L........................... ..hpage....x........................... ..hinit.........-.......-.............. ..h.rdata.......-.......-..........
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):14592
Entropy (8bit):6.033771703962439
Encrypted:false
SSDEEP:
MD5:599F3715602F4CB09AD0FDC606E3B9D9
SHA1:659F9A1CF662260F3FB197E6FE3592922014E831
SHA-256:589FEA41EF48ACD9F0FC54AB25A430E5627D17E8EC3C950F3C5CB71C348E9B8D
SHA-512:56E55D7FD6330E2BBE60BD79D7502E22CEDC9F448982C54E9C924BD57B3C0741E634883435BA4621DB80852D7F47A081FA4FA4302217BFB4BF87558F7EC233BB
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................`...........!..L.!This program cannot be run in DOS mode....$.........................................................................................................................................................................................................................................................................................................................................................................................................T.Q.:.Q.:.Q.:.v.G.R.:.v.A.S.:.Q.;.}.:...).V.:.v.W.T.:.v.T.T.:.v.F.P.:.v.B.P.:.RichQ.:.........PE..L...}.?L.................+...................+...............................9.......Y......................................D...d....3..8....................7.......+...............................+..@............+...............................text............................... ..hpage....~........................... ..hinit.........*.......*.............. ..h.rdata.. ....+.......+..
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
Category:dropped
Size (bytes):2769
Entropy (8bit):2.920806790606985
Encrypted:false
SSDEEP:
MD5:AA080089651F6FB5A8FCAFDCDBAF2861
SHA1:92E7BB03D56F1D11ABE3C026E0E45DEEFD110F8D
SHA-256:B89A0A6A153545187FB2D7B6DD75416784988D4FDAF19666A82EE3A3C08E3699
SHA-512:12187937A2E47F9AEEB2F7754AD32299637061BB39B64B6257FB09FC1ACB4A8A5F439C15EE4899665B4C3677244C4ED70418F5D63528C58E314B187F32C00DC2
Malicious:false
Reputation:unknown
Preview:L..................F.P......................................................-....P.O. .:i.....+00.../C:\...................V.1......Y....Windows.@......OwH.Y......3.....................;.S.W.i.n.d.o.w.s.....\.1......Y....Installer.D......O.I.Y..............................4.I.n.s.t.a.l.l.e.r.......1......Y....{B4E4E~1..~.......Y...Y......<.....................db3.{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.......2......Y..!.EASYLO~1.EXE..........Y...Y......>.....................db3.E.a.s.y.L.o.g._.U.S.B...e.x.e._.6.3.2.5.7.A.9.3.0.1.F.B.4.E.A.B.A.0.8.5.D.3.C.6.9.F.4.7.0.E.C.4...e.x.e.............\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.\.E.a.s.y.L.o.g._.U.S.B...e.x.e._.6.3.2.5.7.A.9.3.0.1.F.B.4.E.A.B.A.0.8.5.D.3.C.6.9.F.4.7.0.E.C.4...e.x.e.#.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.p.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
Category:dropped
Size (bytes):2775
Entropy (8bit):2.927642390330706
Encrypted:false
SSDEEP:
MD5:A0E431F9BC1DFE9DB59F352D16BBAE1D
SHA1:DD809A06818B7888E8F8320D5E55205105563CE5
SHA-256:3241D2306291990F25A3CEBFC2C3E76CBCE62BA1B6552E0127594BA5BAB557DC
SHA-512:F22BD60F8A0D79E33B07BBB6A03D9800AD403B7610A6641E62BF4A154D9893C835CEB7635068C01BBEC33C9E4EA9707887948DF8B18FB84E6E257E5E9D6BC40D
Malicious:false
Reputation:unknown
Preview:L..................F.P....................................................../....P.O. .:i.....+00.../C:\...................V.1......Y....Windows.@......OwH.Y......3.....................;.S.W.i.n.d.o.w.s.....\.1......Y....Installer.D......O.I.Y..............................4.I.n.s.t.a.l.l.e.r.......1......Y....{B4E4E~1..~.......Y...Y......<.......................1.{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.......2......Y..!.EASYLO~2.EXE..........Y...Y......?.....................t.1.E.a.s.y.L.o.g.G.r.a.p.h...e.x.e._.3.D.3.9.C.6.0.5.F.6.D.0.4.8.4.A.8.8.F.3.A.D.4.B.8.2.B.1.3.9.9.3...e.x.e.............\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.\.E.a.s.y.L.o.g.G.r.a.p.h...e.x.e._.3.D.3.9.C.6.0.5.F.6.D.0.4.8.4.A.8.8.F.3.A.D.4.B.8.2.B.1.3.9.9.3...e.x.e.#.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.q.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Feb 18 18:11:02 2021, mtime=Thu Aug 29 17:48:03 2024, atime=Thu Feb 18 18:11:02 2021, length=2468864, window=hide
Category:dropped
Size (bytes):970
Entropy (8bit):4.689725428246736
Encrypted:false
SSDEEP:
MD5:5880D542141D83B403798CC70F0F8DDD
SHA1:9CD568471200DB0F901DFEDB846576CCF7613439
SHA-256:209CDB20C2078A3DCCF2FC9ED735FA4E6776324BA3D2122123618574D41DDEF2
SHA-512:D45CB5FF8419D6A9830384C6541060F1FC7C8AA080E602308E6F2A8E625FF83AC0493463735121739472A67A6EC7D524F84BB1CDDA8CC71B9AAD61CF7A809021
Malicious:false
Reputation:unknown
Preview:L..................F.... ....g2.)...$.l.C....g2.).....%..........................P.O. .:i.....+00.../C:\.....................1......Y....PROGRA~2.........O.I.Y......................V........P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....`.1......Y....EASYLO~1..H.......Y...Y.............................7.E.a.s.y.L.o.g. .U.S.B.....l.2...%.RRa. .EASYLO~1.EXE..P......RRa..Y................................E.a.s.y.L.o.g. .U.S.B...e.x.e.......a...............-.......`.............pw.....C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe..8.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.E.a.s.y.L.o.g. .U.S.B...e.x.e.........*................@Z|...K.J.........`.......X.......238576...........hT..CrF.f4... ..............%..hT..CrF.f4... ..............%.........A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Feb 18 18:11:02 2021, mtime=Thu Aug 29 17:48:03 2024, atime=Thu Feb 18 18:11:02 2021, length=2468864, window=hide
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:5880D542141D83B403798CC70F0F8DDD
SHA1:9CD568471200DB0F901DFEDB846576CCF7613439
SHA-256:209CDB20C2078A3DCCF2FC9ED735FA4E6776324BA3D2122123618574D41DDEF2
SHA-512:D45CB5FF8419D6A9830384C6541060F1FC7C8AA080E602308E6F2A8E625FF83AC0493463735121739472A67A6EC7D524F84BB1CDDA8CC71B9AAD61CF7A809021
Malicious:false
Reputation:unknown
Preview:L..................F.... ....g2.)...$.l.C....g2.).....%..........................P.O. .:i.....+00.../C:\.....................1......Y....PROGRA~2.........O.I.Y......................V........P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....`.1......Y....EASYLO~1..H.......Y...Y.............................7.E.a.s.y.L.o.g. .U.S.B.....l.2...%.RRa. .EASYLO~1.EXE..P......RRa..Y................................E.a.s.y.L.o.g. .U.S.B...e.x.e.......a...............-.......`.............pw.....C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe..8.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.E.a.s.y.L.o.g. .U.S.B...e.x.e.........*................@Z|...K.J.........`.......X.......238576...........hT..CrF.f4... ..............%..hT..CrF.f4... ..............%.........A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Feb 18 18:11:02 2021, mtime=Thu Aug 29 17:48:03 2024, atime=Thu Feb 18 18:11:02 2021, length=2468864, window=hide
Category:dropped
Size (bytes):1015
Entropy (8bit):4.716458189532959
Encrypted:false
SSDEEP:
MD5:73FD178A87DEBBBC8B043A607FA6B1BA
SHA1:CB673A934ACBB829E91FD4A4A3ECA849A4494B14
SHA-256:6199E5FD1BFB9B467033D1F3B41E830666C8B4F541289BA281B9466B3EC71121
SHA-512:2613E38C9EEAB9361E1DA6FC745FDE2E7BC0A8118FCA294284BE2DA210B0270356662ACBB34C522227CBA5E13BC6DCBA750ED4530C1B30E153F688E0F6B825F2
Malicious:false
Reputation:unknown
Preview:L..................F.... ....g2.)...$.l.C....g2.).....%..........................P.O. .:i.....+00.../C:\.....................1......Y....PROGRA~2.........O.I.Y......................V........P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....`.1......Y....EASYLO~1..H.......Y...Y.............................7.E.a.s.y.L.o.g. .U.S.B.....l.2...%.RRa. .EASYLO~1.EXE..P......RRa..Y................................E.a.s.y.L.o.g. .U.S.B...e.x.e.......a...............-.......`.............pw.....C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe..8.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.E.a.s.y.L.o.g. .U.S.B...e.x.e.........*................@Z|...K.J.........`.......X.......238576...........hT..CrF.f4... ..............%..hT..CrF.f4... ..............%.........-...1SPSU(L.y.9K....-........................A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?.
Process:C:\Windows\SysWOW64\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):205
Entropy (8bit):5.239236705496828
Encrypted:false
SSDEEP:
MD5:52E37704F6B2D0A60914D4FC33BB8392
SHA1:865DE5AD56B952BC6A55A44A9B25C5982B08856D
SHA-256:80D350EEFE5A06D8D5939421EA8AA11227E1CB7531405D44D236F7C520BD1D26
SHA-512:19EBDD5C7765B6C4CF3F10B76550679345B51F0C38C6081DC9B8F6DE1ADD700F7124A8CF7CB948FB6E494DA607677A646ADDE50E6C748C41526DE6B698425215
Malicious:false
Reputation:unknown
Preview:[DLL1]..Return=void..Module=user32.dll..Func=MessageBoxA..Arg0=in,MsiWindowHandle,NUMBER..Arg1=in,[MESSAGEPROP],STRING..Arg2=in,[CAPTIONPROP],STRING..Arg3=in,1,NUMBER..Silent=Yes..Source=Local,user32.dll..
Process:C:\Windows\SysWOW64\msiexec.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):156928
Entropy (8bit):6.027572827219195
Encrypted:false
SSDEEP:
MD5:69E9BB71D4D394E87F0109734D328371
SHA1:82FBEF8F36AECEFBCA489D58C09CDF4B0386F787
SHA-256:C3A87617D5BA229A62DA7FD4E0929BE26CAC33C58470FD5E5F0B54C30FF4D172
SHA-512:867C051E8BEAD1B4B093833776B2643E2B077E5D0866FF0D5362EA51AD277C3FF0F6892475183F4308409742DE63FFEED6289FBE4BD6DA692F873EF647AE3414
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........;..;..;....#.*.... .=... .:....!...... .H..2.m.8..2.}.$..;..6...!.-...$.:...'.:..;.y.:...".:..Rich;..........PE..L...y..W...........!.....J..........F........`......................................7...............................p...E............@...............H.......P..@...................................H...@............`...............................text....I.......J.................. ..`.rdata.......`.......N..............@..@.data...t1..........................@....rsrc........@......................@..@.reloc...J...P...L..................@..B................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\EasyLogUSB+Installer.exe
File Type:Unicode text, UTF-16, little-endian text, with very long lines (308), with CRLF line terminators
Category:dropped
Size (bytes):22480
Entropy (8bit):3.4851320007899904
Encrypted:false
SSDEEP:
MD5:A108F0030A2CDA00405281014F897241
SHA1:D112325FA45664272B08EF5E8FF8C85382EBB991
SHA-256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948
SHA-512:D83894B039316C38915A789920758664257680DCB549A9B740CF5361ADDBEE4D4A96A3FF2999B5D8ACFB1D9336DA055EC20012D29A9F83EE5459F103FBEEC298
Malicious:false
Reputation:unknown
Preview:..[.0.x.0.4.0.9.].....1.1.0.0.=.S.e.t.u.p. .I.n.i.t.i.a.l.i.z.a.t.i.o.n. .E.r.r.o.r.....1.1.0.1.=.%.s.....1.1.0.2.=.%.1. .S.e.t.u.p. .i.s. .p.r.e.p.a.r.i.n.g. .t.h.e. .%.2.,. .w.h.i.c.h. .w.i.l.l. .g.u.i.d.e. .y.o.u. .t.h.r.o.u.g.h. .t.h.e. .p.r.o.g.r.a.m. .s.e.t.u.p. .p.r.o.c.e.s.s... . .P.l.e.a.s.e. .w.a.i.t.......1.1.0.3.=.C.h.e.c.k.i.n.g. .O.p.e.r.a.t.i.n.g. .S.y.s.t.e.m. .V.e.r.s.i.o.n.....1.1.0.4.=.C.h.e.c.k.i.n.g. .W.i.n.d.o.w.s.(.R.). .I.n.s.t.a.l.l.e.r. .V.e.r.s.i.o.n.....1.1.0.5.=.C.o.n.f.i.g.u.r.i.n.g. .W.i.n.d.o.w.s. .I.n.s.t.a.l.l.e.r.....1.1.0.6.=.C.o.n.f.i.g.u.r.i.n.g. .%.s.....1.1.0.7.=.S.e.t.u.p. .h.a.s. .c.o.m.p.l.e.t.e.d. .c.o.n.f.i.g.u.r.i.n.g. .t.h.e. .W.i.n.d.o.w.s. .I.n.s.t.a.l.l.e.r. .o.n. .y.o.u.r. .s.y.s.t.e.m... .T.h.e. .s.y.s.t.e.m. .n.e.e.d.s. .t.o. .b.e. .r.e.s.t.a.r.t.e.d. .i.n. .o.r.d.e.r. .t.o. .c.o.n.t.i.n.u.e. .w.i.t.h. .t.h.e. .i.n.s.t.a.l.l.a.t.i.o.n... .P.l.e.a.s.e. .c.l.i.c.k. .R.e.s.t.a.r.t. .t.o. .r.e.b.o.o.t. .t.h.e. .s.y.s.t.e.m.......1.1.0.8.
Process:C:\Users\user\Desktop\EasyLogUSB+Installer.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Number of Characters: 0, Last Saved By: InstallShield, Number of Words: 0, Title: Installation Database, Comments: Contact: Your local administrator, Keywords: Installer,MSI,Database, Subject: EasyLog USB, Author: Lascar Electronics Ltd., Security: 1, Number of Pages: 200, Name of Creating Application: InstallShield 2016 - Professional Edition 23, Last Saved Time/Date: Mon Aug 8 16:29:11 2022, Create Time/Date: Mon Aug 8 16:29:11 2022, Last Printed: Mon Aug 8 16:29:11 2022, Revision Number: {8C7E2C80-4C6F-4A5C-9FDD-5AA316A9E29A}, Code page: 1252, Template: Intel;1033
Category:dropped
Size (bytes):19083776
Entropy (8bit):7.960074563695781
Encrypted:false
SSDEEP:
MD5:0667825A7C186AB1769BEF4A2D0D5CA6
SHA1:06EFBC582B852C4964CA6CA1DEFB5B13B182B0BA
SHA-256:A0875FA7ABF8474D2864DAFA61CCA887F0EA81ED0B82B57184046A1E946E4C10
SHA-512:ECCF9D7FA57095BF4CDECA50DA10BF8CA2B8AAD5C756D3B7E3CEE55D4976D894B1ED5AE9D512950835EED696FD3A7DB1DB0ADB878EEC178103461C9443C62697
Malicious:false
Reputation:unknown
Preview:......................>...................$...............8........6....................................................................................................................................................................................................................................................................... ... ...!...!..."..."...#...#...$...$...%...%...&...&...'...'...(...(...)...)...*...*...+...+...,...,...-...-.........../.../...0...0...1...1...2...2...3...3...4...4...5...5...6..........;...............................................................................................!................... ...#..."...-...$.......&...'...(...)...*...+...,.../.......1...0...D...2...3...4...5...6...7...A...M...:...<.......=.......?...@...R...B...C...F...E...Z...G...H...I...J...O...L...N...k.......P...Q...T...S...~...U...\...W...X...Y...|...[.......]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
Process:C:\Users\user\Desktop\EasyLogUSB+Installer.exe
File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):20
Entropy (8bit):2.8954618442383215
Encrypted:false
SSDEEP:
MD5:DB9AF7503F195DF96593AC42D5519075
SHA1:1B487531BAD10F77750B8A50ACA48593379E5F56
SHA-256:0A33C5DFFABCF31A1F6802026E9E2EEF4B285E57FD79D52FDCD98D6502D14B13
SHA-512:6839264E14576FE190260A4B82AFC11C88E50593A20113483851BF4ABFDB7CCA9986BEF83F4C6B8F98EF4D426F07024CF869E8AB393DF6D2B743B9B8E2544E1B
Malicious:false
Reputation:unknown
Preview:..[.F.i.l.e.s.].....
Process:C:\Users\user\Desktop\EasyLogUSB+Installer.exe
File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):5252
Entropy (8bit):3.733760690252317
Encrypted:false
SSDEEP:
MD5:33F13D68A9E9F9845760A257286545AA
SHA1:A2B07B4FBF4BFCCFF550469FC12C7030892D9355
SHA-256:A231E341F8E0997464F740BEC5526711605B173DC2C3101D580DB82AB636E67A
SHA-512:55455655ADA80A5BFC15BD9878FE8DD7B60FCBD5800A13C06BCC8E5400D08FE5684E565DBC2B9E87FA8CCEF96CBF58B4045D59F60809A7B7C41A737D776F3C81
Malicious:false
Reputation:unknown
Preview:..[.I.n.f.o.].....N.a.m.e.=.I.N.T.L.....V.e.r.s.i.o.n.=.1...0.0...0.0.0.....D.i.s.k.S.p.a.c.e.=.8.0.0.0...;.D.i.s.k.S.p.a.c.e. .r.e.q.u.i.r.e.m.e.n.t. .i.n. .K.B.........[.S.t.a.r.t.u.p.].....C.m.d.L.i.n.e.=.....S.u.p.p.r.e.s.s.W.r.o.n.g.O.S.=.Y.....S.c.r.i.p.t.D.r.i.v.e.n.=.0.....S.c.r.i.p.t.V.e.r.=.1...0...0...1.....D.o.t.N.e.t.O.p.t.i.o.n.a.l.I.n.s.t.a.l.l.I.f.S.i.l.e.n.t.=.N.....O.n.U.p.g.r.a.d.e.=.0.....P.r.o.d.u.c.t.=.E.a.s.y.L.o.g. .U.S.B.....P.a.c.k.a.g.e.N.a.m.e.=.E.a.s.y.L.o.g. .U.S.B...m.s.i.....E.n.a.b.l.e.L.a.n.g.D.l.g.=.N.....L.o.g.R.e.s.u.l.t.s.=.N.....D.o.M.a.i.n.t.e.n.a.n.c.e.=.N.....P.r.o.d.u.c.t.C.o.d.e.=.{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.....P.r.o.d.u.c.t.V.e.r.s.i.o.n.=.7...7...0.....U.p.g.r.a.d.e.C.o.d.e.=.{.3.1.5.0.0.6.0.B.-.C.0.3.B.-.4.0.B.D.-.8.5.9.1.-.5.A.E.7.5.2.0.9.7.F.0.B.}.....L.a.u.n.c.h.e.r.N.a.m.e.=.E.a.s.y.L.o.g.U.S.B._.V.7.-.7.0._.I.n.s.t.a.l.l._.U.p.d.a.t.e...e.x.e.....P.a.c.k.a.g.e.C.o.d.e.=.{.8.C.7.E.2.C.8.
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):523512
Entropy (8bit):6.417003787731374
Encrypted:false
SSDEEP:
MD5:557E647D925831D32DA575BF45C849D7
SHA1:50B607E57D527CD076BE0BA23E1177890A401C12
SHA-256:E41012393DACFDF2632243323D5718EA962ED96FD8248D1C6747903E4C2A1D36
SHA-512:DB5F067EFADE41BB5B7E3B54CC1FF40AD3105CB2258329C13C92E38B29CB9E62EA2C1FFAA2401FA8E34BE16C7CBB87F6CBA5AEA88B79361181C9A81D3612E53E
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......b.o.&o..&o..&o....+o....Bo.....o../...-o..&o..\o......o.....'o.....'o..&o..'o.....'o..Rich&o..................PE..L....}.W...........!.....V..................p...............................0............@..........................(..rB......x................................d...r..8...............................@............p...............................text...#T.......V.................. ..`.rdata..R....p.......Z..............@..@.data...|4...p.......V..............@....rsrc................l..............@..@.reloc..Ne.......f...z..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):207049
Entropy (8bit):5.187015593802942
Encrypted:false
SSDEEP:
MD5:B3162FFB792F882D3FCF89877784E231
SHA1:8E5885FF2BBFB1C2BD3A2431BF4C88E3846FC535
SHA-256:5472F56D63A2E7CEC34C3576D8B36FD79D7689656A46E8A637E1B2017EC6E303
SHA-512:5082332173E24AA317C9D80F20A84618CCC38DFA0499467B5FAF1809C3ECCD94F6E2BF6D117BE58A9F49193EF346043FD47B784A7B44D4F48CB24CD5E67105C6
Malicious:false
Reputation:unknown
Preview:...@IXOS.@.....@.v.Y.@.....@.....@.....@.....@.....@......&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}..EasyLog USB..EasyLog USB.msi.@.....@.....@.....@......ARPPRODUCTICON.exe..&.{8C7E2C80-4C6F-4A5C-9FDD-5AA316A9E29A}.....@.....@.....@.....@.......@.....@.....@.......@......EasyLog USB......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration...@.....@.....@.]....&.{429FE619-EEB7-4E48-AF7A-4F56DD1C7491}#.C:\Program Files (x86)\EasyLog USB\.@.......@.....@.....@......&.{1D213698-CDE4-4051-B5BD-2BBDFE318583}'.C:\Program Files (x86)\EasyLog USB\x86\.@.......@.....@.....@......&.{B2ECCF77-395E-4A26-A4BF-5EC89425F03F}'.C:\Program Files (x86)\EasyLog USB\x64\.@.......@.....@.....@......&.{AFECBE12-FD2C-45CC-80F8-C71798C38400}1.C:\Program Files (x86)\EasyLog USB\WPFToolkit.dll.@.......@.....@.....@......&.{A058DD12-721A-4A06-81C5-933F86CBD9A8}#.C:\Program Files (x86)\EasyLog USB\.@.......@....
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.1637138209702855
Encrypted:false
SSDEEP:
MD5:8CBB11CC163A88AC880145DE140B5E02
SHA1:AC3E85A196D419FC808FF7BF141E6CBBAC046A1D
SHA-256:0E1ABE831BD1B9F4A7240882FE51E3B1D91FEE18D35C0F4621F8AE604DBE87E8
SHA-512:DFECF49E7561844EAA817CAF0CD14DAB8B1773D9DE1A6F8971EF0E6E3E2C87D6740DE1A9C42CF5499BFDB9B8AB1D414B20D076E5BB2DC9618CA2E5C877C8C961
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):72944
Entropy (8bit):5.067944027835008
Encrypted:false
SSDEEP:
MD5:23C1D640A469D3086A14F9FDF449EB50
SHA1:2F277BA7EC429B93FE4D3879973024F8BACBE832
SHA-256:AE66EC7081CE696B549E39F70E5ADA5F57AC6F8173773EED1144039C24946945
SHA-512:585495B7A633B8F46ACB9D2A78703FB47A6057FC8F22171CC5F1B7EDF627D05571D39A164A15ED718C042C7B6C99AC927E00B83C95954E8EA9AE9E0FF58DC64B
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............C...C...C...C...CD..C...C...C...C=..C...C...C...C...C...CRich...C........................PE..L.../..W.................@...................P....@.................................=;......................................4T..(........^...............,...........................................................P...............................text....5.......@.................. ..`.rdata.......P.......P..............@..@.data....)...`...0...`..............@....rsrc....^.......`..................@..@................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):52464
Entropy (8bit):5.106173623429902
Encrypted:false
SSDEEP:
MD5:6E27FC142F298EEE2A5C37F3DF46975B
SHA1:0348059D4CE805D7099F3E24CF9AF5548C971176
SHA-256:70DCCB008ACA50A9F1925967DF3A15B581623FEF1AF005C5BD6BD59451AA8E79
SHA-512:CA5EC51965E9972946D80BFFFF617B2DFA08C743B1E3B5CF663DBFB79CC4769273B8BD28E6398F4B45E05DA48D8AC57548288018DD25812B001CE430E71A5599
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............C...C...C...C...CD..C...C...C...C=..C...C...C...C...C...CRich...C........................PE..L.../..W.................@...P...............P....@........................................................................4T..(.......,................,...........................................................P...............................text....5.......@.................. ..`.rdata.......P.......P..............@..@.data....)...`...0...`..............@....rsrc...,...........................@..@................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):72944
Entropy (8bit):5.069498628939283
Encrypted:false
SSDEEP:
MD5:A2936C32057A1EC0E7F343B46A1C2D60
SHA1:6FA37460864A7452A0F0E82EB87D59EEAE1058ED
SHA-256:18F7E5E9E33F1A914EE9E64B239B7EB0D7FDC55C7BC2C06FFD97A23E76A8817C
SHA-512:3C78590D5BCE97502BE732683AF6B2B7A6AF14AF5DE80E431F7436C204E68E98D99F136E38317C8196ACB35414571B2253534B1858D01726268E917AFB71E67C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............C...C...C...C...CD..C...C...C...C=..C...C...C...C...C...CRich...C........................PE..L.../..W.................@...................P....@..................................?......................................4T..(........^...............,...........................................................P...............................text....5.......@.................. ..`.rdata.......P.......P..............@..@.data....)...`...0...`..............@....rsrc....^.......`..................@..@................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
Category:dropped
Size (bytes):454234
Entropy (8bit):5.356173939611067
Encrypted:false
SSDEEP:
MD5:48DD1912A723B49B6C7E57E6393B48F6
SHA1:E1D94DCDC256DF156A89978EABDAFF4D74104C45
SHA-256:F7521E9F96368633B1D4937D491D5F7B84AE1AD1E09DF4A0465C16DB2B290FF7
SHA-512:3746726E5C4A270F3AE14525D7195FC82BF0981451D1B3B8FE17877888B997123E10DAEF9E68D873D9FEF517A5A394646DE0CA0BF312E2F93F46C20336EF86DC
Malicious:false
Reputation:unknown
Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):90112
Entropy (8bit):5.1088148238453925
Encrypted:false
SSDEEP:
MD5:372584E745A5A968AA02D7B969FB377B
SHA1:3333F82ED9FBD12CBF79C4E37EC65A7991BF60F5
SHA-256:77BAADD8CF594F91C20DA6F46A0AB939796D03F92AECB5D478049D419AA8DF13
SHA-512:ACE16FF6F7C2170712FCD4801B396BA54ECD0B20FCD82C7653F8294F69296493E0CA1748457D6A19AB060F3A43D4645A8A9C084E11F0C582C23E40A53AD5D6BC
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........=r..\...\...\..H@...\...z..\..C...\..C...\...\..\...z...\...Z...\..4|...\..Rich.\..................PE..L...y..I...........!................7Y.......................................`..............................................P...d....0.......................@..x.......................................................@............................text...b........................... ..`.rdata..h........ ..................@..@.data....9.......@..................@....rsrc........0.......0..............@..@.reloc..B....@... ...@..............@..B................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.4569539727621832
Encrypted:false
SSDEEP:
MD5:8B48F7A9C695481856FBD31600430B7B
SHA1:B5CE14298751CDBF07E6759514D83C83CD19A878
SHA-256:9B4AD2D50F951E4A48FB1CFBD916E2F9AAFB485348E0BF5A2D852ADF7B895937
SHA-512:75BD13D06C09DD99139C31006F33091603BDEE0FBE90DBC6C8DB985D9C60E5B299A822446A48A8A2F460326EB23582315280FF6E55C10604B796A31ECDC6785E
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):32768
Entropy (8bit):0.07156909361014326
Encrypted:false
SSDEEP:
MD5:C20051FAD9BF592298D88B23073C7758
SHA1:203F35B2A93DC8E0896D7E65C081AA593D8F5089
SHA-256:8EDE3DA36D4A8A1EEB706EABB21DC8B2DAAB0FC6CF0D74818EBBC8EECA02EE3B
SHA-512:043EE68EF5C36C158E5355BBBABC74AC6AEEBCC68AFEF6E7FEA368C31CD2B7451AF44F8DEFC6445FAFF0D631337F0D319B91AEC4FE8606BB9230B4DB5A18AA88
Malicious:false
Reputation:unknown
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.8452524929988765
Encrypted:false
SSDEEP:
MD5:360975D4BE45E1E52975901D70E593E9
SHA1:675F2FE1EA01F0E0D55E981E6D749E048C77F4BF
SHA-256:1379408CBCD107296C5B90EB6FCFB974CB6C6E11D08E0DEC3015D25185140406
SHA-512:E0296619EB1AA51B9319E668ABF8918B50F7A55010213DF9001DE40B289BECA538842EDD17846AA2906CA49E5154D745B205E60B76051FBC7980F878BD65F31F
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):73728
Entropy (8bit):0.24189976504386393
Encrypted:false
SSDEEP:
MD5:2D851F40F33E23A9DA0A4DEDCC555688
SHA1:D009E2CBA92A23900AADFCA0BE07EBC8788997C2
SHA-256:2171FDF033F9E7E824EB444BD0986560E7D8FE4CD35372DF1963CAA7FE396D54
SHA-512:C4AD4AD058D74AB1C207784448B6BC3D3AECD3E9F7A2AB43AA9437F019EE30ADE683202842B8FFD5578533DD7CC3F92F3F47EF6A40D545E3D8E1C1A66C4BC7CD
Malicious:false
Reputation:unknown
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Reputation:unknown
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.982918880423008
TrID:
  • Win32 Executable (generic) a (10002005/4) 99.96%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:EasyLogUSB+Installer.exe
File size:19'500'624 bytes
MD5:d3d4273692e34102b88c513ad1c10040
SHA1:1b75e5c2644fbf075040df437b15d4d2c128c2cf
SHA256:cc2652dc33020fab609750a6f627e2f8e6597960b25f210981e62f5ad92f7d70
SHA512:94ea2dedb53887a40b4995536211d94247b3bd9994e0b3888eedffa52a20b4cd500a4da86f110a7a203ba2802b011d29c349774df8d4bea5ea3237f216e1157b
SSDEEP:393216:BhQWQwqV7x2GH3mm+xaYzY4VGHxfwzXUxnIbG1vrMd:Bjqd9WJaYz7GRfwLUxnIbcYd
TLSH:49172323B581903ED5A102328C6FAD7081A97EB35E31465BF698FF1D1DF48827927F1A
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........wn.............................M.......M...7...@a......M.......@a..........!...................................Rich...........
Icon Hash:497971328ce1634d
Entrypoint:0x4575cc
Entrypoint Section:.text
Digitally signed:true
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
DLL Characteristics:NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x57B8A2BE [Sat Aug 20 18:34:38 2016 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:5
OS Version Minor:1
File Version Major:5
File Version Minor:1
Subsystem Version Major:5
Subsystem Version Minor:1
Import Hash:4da036c357ba9b57ad512acda2ab8f70
Signature Valid:true
Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
Signature Validation Error:The operation completed successfully
Error Number:0
Not Before, Not After
  • 25/01/2022 01:00:00 24/01/2023 00:59:59
Subject Chain
  • CN=Lascar Electronics Ltd., O=Lascar Electronics Ltd., L=Salisbury, C=GB
Version:3
Thumbprint MD5:B656567D8713E66AE810DFDEF09BAA4E
Thumbprint SHA-1:E120C7DAC8262B2FC234FFDD7FEF64DB785FF6E4
Thumbprint SHA-256:470E7DEBE4EF2ED0668130574D9D743A3146EC84E67B32537A42A506442399B0
Serial:0129746216985DDDF8A35EE9CD1C24B9
Instruction
call 00007F5554F08C62h
jmp 00007F5554EF9F1Eh
push ebp
mov ebp, esp
mov eax, dword ptr [ebp+14h]
push esi
test eax, eax
je 00007F5554EFA11Eh
cmp dword ptr [ebp+08h], 00000000h
jne 00007F5554EFA0F5h
call 00007F5554EF84CEh
push 00000016h
pop esi
mov dword ptr [eax], esi
call 00007F5554EFCC4Eh
mov eax, esi
jmp 00007F5554EFA107h
cmp dword ptr [ebp+10h], 00000000h
je 00007F5554EFA0C9h
cmp dword ptr [ebp+0Ch], eax
jnc 00007F5554EFA0EBh
call 00007F5554EF84B0h
push 00000022h
jmp 00007F5554EFA0C2h
push eax
push dword ptr [ebp+10h]
push dword ptr [ebp+08h]
call 00007F5554EF5F5Bh
add esp, 0Ch
xor eax, eax
pop esi
pop ebp
ret
push ebp
mov ebp, esp
xor edx, edx
mov eax, edx
cmp dword ptr [ebp+0Ch], eax
jbe 00007F5554EFA0F3h
mov ecx, dword ptr [ebp+08h]
cmp word ptr [ecx], dx
je 00007F5554EFA0EBh
inc eax
add ecx, 02h
cmp eax, dword ptr [ebp+0Ch]
jc 00007F5554EFA0D4h
pop ebp
ret
test eax, eax
jne 00007F5554EFA0E8h
pxor xmm0, xmm0
jmp 00007F5554EFA0F3h
movd xmm0, eax
punpcklbw xmm0, xmm0
punpcklwd xmm0, xmm0
pshufd xmm0, xmm0, 00h
push ebx
push ecx
mov ebx, ecx
and ebx, 0Fh
test ebx, ebx
jne 00007F5554EFA15Ah
mov ebx, edx
and edx, 7Fh
shr ebx, 07h
je 00007F5554EFA112h
movdqa dqword ptr [ecx], xmm0
movdqa dqword ptr [ecx+10h], xmm0
movdqa dqword ptr [ecx+20h], xmm0
movdqa dqword ptr [ecx+30h], xmm0
movdqa dqword ptr [ecx+40h], xmm0
movdqa dqword ptr [ecx+50h], xmm0
movdqa dqword ptr [ecx+60h], xmm0
Programming Language:
  • [ C ] VS2012 UPD1 build 51106
  • [C++] VS2012 UPD1 build 51106
  • [RES] VS2012 UPD1 build 51106
  • [LNK] VS2012 UPD1 build 51106
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0xe963c0xc8.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0xf50000x4cc9c.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x12961300x2d20
IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
IMAGE_DIRECTORY_ENTRY_DEBUG0xb56800x38.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xcec400x40.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0xb50000x584.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xe8cf00xe0.rdata
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000xb31450xb32003c5019b481b36b50861c003b927571feFalse0.4942537508722959data6.587897407968807IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0xb50000x363a20x364009ccda080685d04b6d39abf90df4ddb2eFalse0.4168391777073733data5.111602563063982IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0xec0000x8c380x2800ac1123bbcdd1c65593b571a2c4af0630False0.29013671875data4.4690563880861IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc0xf50000x4cc9c0x4ce004266bd2112a8e5f29d2d02ae8b566503False0.33817962398373985data6.561419459411344IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
GIF0xf5dcc0x33a7GIF image data, version 89a, 350 x 6240.9106859260379642
GIF0xf91740x339fGIF image data, version 89a, 350 x 624EnglishUnited States0.9129020052970109
PNG0xfc5140x39edPNG image data, 360 x 150, 8-bit/color RGBA, non-interlaced0.9975723244992919
PNG0xfff040x2fc9PNG image data, 240 x 227, 8-bit/color RGBA, non-interlaced0.9968119022316685
RT_BITMAP0x102ed00x14220Device independent bitmap graphic, 220 x 370 x 8, image size 814000.34390764454792394
RT_BITMAP0x1170f00x1b5cDevice independent bitmap graphic, 180 x 75 x 4, image size 69000.18046830382638493
RT_BITMAP0x118c4c0x38e4Device independent bitmap graphic, 180 x 75 x 8, image size 135000.26689096402087337
RT_BITMAP0x11c5300x1238Device independent bitmap graphic, 60 x 60 x 8, image size 36000.23499142367066894
RT_BITMAP0x11d7680x6588Device independent bitmap graphic, 161 x 152 x 8, image size 24928, resolution 3796 x 3796 px/m, 256 important colors0.3035934133579563
RT_BITMAP0x123cf00x11f88Device independent bitmap graphic, 161 x 152 x 24, image size 73568, resolution 3780 x 3780 px/m0.12790729268557766
RT_ICON0x135c780x468Device independent bitmap graphic, 16 x 32 x 32, image size 10240.21808510638297873
RT_ICON0x1360e00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 40960.099906191369606
RT_ICON0x1371880x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 92160.06109958506224066
RT_ICON0x1397300x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 6400.35618279569892475
RT_ICON0x139a180x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 6400.42473118279569894
RT_DIALOG0x139d000x1cedata0.48917748917748916
RT_DIALOG0x139ed00x266data0.4527687296416938
RT_DIALOG0x13a1380x2b0data0.438953488372093
RT_DIALOG0x13a3e80x54data0.6904761904761905
RT_DIALOG0x13a43c0x34data0.8846153846153846
RT_DIALOG0x13a4700xd6data0.6495327102803738
RT_DIALOG0x13a5480x114data0.5036231884057971
RT_DIALOG0x13a65c0xd6data0.5841121495327103
RT_DIALOG0x13a7340x246data0.4690721649484536
RT_DIALOG0x13a97c0x3c8data0.4194214876033058
RT_DIALOG0x13ad440x14edata0.5359281437125748
RT_DIALOG0x13ae940x1e8data0.49385245901639346
RT_DIALOG0x13b07c0x1c6data0.5286343612334802
RT_DIALOG0x13b2440x1eedata0.49190283400809715
RT_DIALOG0x13b4340x7cdata0.7580645161290323
RT_DIALOG0x13b4b00x3bcdata0.4372384937238494
RT_DIALOG0x13b86c0x158data0.5581395348837209
RT_DIALOG0x13b9c40x1dadata0.5168776371308017
RT_DIALOG0x13bba00x10adata0.6015037593984962
RT_DIALOG0x13bcac0xdedata0.6441441441441441
RT_DIALOG0x13bd8c0x1d4data0.5085470085470085
RT_DIALOG0x13bf600x1dcdata0.5210084033613446
RT_DIALOG0x13c13c0x294data0.48787878787878786
RT_STRING0x13c3d00x160dataEnglishUnited States0.5340909090909091
RT_STRING0x13c5300x23edataEnglishUnited States0.40418118466898956
RT_STRING0x13c7700x378dataEnglishUnited States0.4222972972972973
RT_STRING0x13cae80x252dataEnglishUnited States0.4393939393939394
RT_STRING0x13cd3c0x1f4dataEnglishUnited States0.442
RT_STRING0x13cf300x66adataEnglishUnited States0.3617539585870889
RT_STRING0x13d59c0x366dataEnglishUnited States0.41379310344827586
RT_STRING0x13d9040x27edataEnglishUnited States0.4561128526645768
RT_STRING0x13db840x518dataEnglishUnited States0.39800613496932513
RT_STRING0x13e09c0x882dataEnglishUnited States0.3002754820936639
RT_STRING0x13e9200x23edataEnglishUnited States0.45121951219512196
RT_STRING0x13eb600x3badataEnglishUnited States0.3280922431865828
RT_STRING0x13ef1c0x12cdataEnglishUnited States0.5266666666666666
RT_STRING0x13f0480x4adataEnglishUnited States0.6756756756756757
RT_STRING0x13f0940xdadataEnglishUnited States0.6100917431192661
RT_STRING0x13f1700x110dataEnglishUnited States0.5845588235294118
RT_STRING0x13f2800x20adataEnglishUnited States0.4521072796934866
RT_STRING0x13f48c0xbaMatlab v4 mat-file (little endian) P, numeric, rows 0, columns 0EnglishUnited States0.5860215053763441
RT_STRING0x13f5480xa8dataEnglishUnited States0.6607142857142857
RT_STRING0x13f5f00x12adataEnglishUnited States0.5201342281879194
RT_STRING0x13f71c0x422dataEnglishUnited States0.2741020793950851
RT_STRING0x13fb400x5c2dataEnglishUnited States0.37720488466757124
RT_STRING0x1401040x40dataEnglishUnited States0.671875
RT_STRING0x1401440xcaadataEnglishUnited States0.2313386798272671
RT_STRING0x140df00x284dataEnglishUnited States0.4363354037267081
RT_GROUP_ICON0x1410740x30data0.8125
RT_GROUP_ICON0x1410a40x14data1.25
RT_GROUP_ICON0x1410b80x14data1.2
RT_VERSION0x1410cc0x424data0.4349056603773585
RT_MANIFEST0x1414f00x52aXML 1.0 document, ASCII text, with CRLF line terminators0.46520423600605143
RT_MANIFEST0x141a1c0x280XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.553125
DLLImport
COMCTL32.dll
KERNEL32.dllLoadLibraryW, lstrcmpW, lstrcmpiW, GetSystemDefaultLangID, GetUserDefaultLangID, VerLanguageNameW, CompareFileTime, CreateDirectoryW, FindClose, FindFirstFileW, FindNextFileW, SetFileAttributesW, GetSystemTimeAsFileTime, GetPrivateProfileStringW, MoveFileW, LocalFree, FormatMessageW, GetSystemInfo, MulDiv, RaiseException, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LoadLibraryExW, GetVersion, GetLocalTime, IsValidLocale, GetCommandLineW, GetFileAttributesW, GlobalAlloc, GlobalFree, FlushFileBuffers, SetEndOfFile, VirtualQuery, lstrcpyA, IsBadReadPtr, GetDiskFreeSpaceExW, GetDriveTypeW, GetExitCodeProcess, GetCurrentThread, GetLocaleInfoW, InterlockedExchange, LoadLibraryExA, DecodePointer, LCMapStringW, RtlUnwind, IsDebuggerPresent, MoveFileExW, WriteProcessMemory, VirtualProtectEx, GetSystemDirectoryW, FreeLibrary, SetThreadContext, GetThreadContext, CreateProcessW, ResumeThread, TerminateProcess, ExitProcess, GetCurrentProcess, Sleep, WaitForSingleObject, DuplicateHandle, RemoveDirectoryW, DeleteFileW, SetCurrentDirectoryW, lstrlenW, lstrcpynA, LocalAlloc, lstrcmpA, SystemTimeToFileTime, ResetEvent, SetEvent, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, GetCurrentDirectoryW, FindResourceExW, GetEnvironmentVariableW, SetFileTime, GetFileTime, OpenProcess, GetProcessTimes, ReadConsoleW, WriteConsoleW, SetStdHandle, SetFilePointerEx, GetConsoleMode, GetConsoleCP, FatalAppExitA, EnumSystemLocalesW, GetUserDefaultLCID, GetTimeFormatW, GetDateFormatW, SetConsoleCtrlHandler, OutputDebugStringW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCurrentProcessId, QueryPerformanceCounter, GetFileType, HeapReAlloc, CreateSemaphoreW, GetStartupInfoW, TlsFree, TlsSetValue, IsProcessorFeaturePresent, CompareStringA, CompareStringW, lstrcatW, GetVersionExW, InterlockedDecrement, InterlockedIncrement, CreateEventW, QueryPerformanceFrequency, GetTempFileNameW, CopyFileW, GetTickCount, GetExitCodeThread, CreateThread, FindResourceW, GlobalUnlock, GlobalLock, SizeofResource, LockResource, LoadResource, lstrcpyW, GetWindowsDirectoryW, SetErrorMode, GetTempPathW, FlushInstructionCache, ExpandEnvironmentStringsW, lstrcpynW, GetModuleFileNameW, GetProcessHeap, HeapFree, HeapAlloc, WriteFile, SetFilePointer, ReadFile, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, CloseHandle, GetFileSize, CreateFileW, SetLastError, GetLastError, LoadLibraryA, GetSystemDirectoryA, GetProcAddress, GetModuleHandleW, TlsGetValue, TlsAlloc, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetStringTypeW, GetCPInfo, GetOEMCP, GetACP, IsValidCodePage, GetCurrentThreadId, HeapSize, AreFileApisANSI, GetModuleHandleExW, GetStdHandle, EncodePointer
USER32.dllCreateWindowExW, SetTimer, KillTimer, LoadCursorW, RegisterClassW, DefWindowProcW, PostMessageW, DispatchMessageW, TranslateMessage, GetMessageW, PostQuitMessage, GetSysColorBrush, CharPrevW, SendDlgItemMessageW, wvsprintfW, LoadImageW, CreateDialogParamW, MoveWindow, SetCursor, GetWindow, GetDlgItemTextW, SetFocus, EnableWindow, SetForegroundWindow, SetActiveWindow, SetDlgItemTextW, IsDialogMessageW, FindWindowW, SubtractRect, IntersectRect, SetRect, FillRect, GetSysColor, GetWindowRect, GetDC, GetSystemMetrics, GetDlgCtrlID, CreateDialogIndirectParamW, DestroyWindow, IsWindow, SendMessageW, MessageBoxW, CharNextW, WaitForInputIdle, SetWindowLongW, GetWindowLongW, GetClientRect, EndPaint, BeginPaint, ReleaseDC, ExitWindowsEx, CharUpperW, GetWindowDC, SetWindowPos, SetWindowTextW, GetDlgItem, EndDialog, DialogBoxIndirectParamW, ShowWindow, GetDesktopWindow, MsgWaitForMultipleObjects, PeekMessageW, wsprintfW, LoadIconW
GDI32.dllUnrealizeObject, CreateHalftonePalette, GetDIBColorTable, SelectPalette, RealizePalette, GetSystemPaletteEntries, CreatePalette, CreateFontW, GetObjectW, SetTextColor, SetBkMode, GetDeviceCaps, CreateSolidBrush, CreateFontIndirectW, SetStretchBltMode, StretchBlt, SelectObject, DeleteDC, CreateDIBitmap, CreateCompatibleDC, BitBlt, DeleteObject, GetStockObject, TranslateCharsetInfo
ADVAPI32.dllCryptCreateHash, CryptSignHashW, GetTokenInformation, FreeSid, EqualSid, AllocateAndInitializeSid, OpenThreadToken, OpenProcessToken, SetEntriesInAclW, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, CreateWellKnownSid, RegQueryInfoKeyW, RegEnumKeyExW, RegDeleteKeyW, RegSetValueExW, RegEnumValueW, RegCreateKeyExW, RegDeleteValueW, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, AdjustTokenPrivileges, LookupPrivilegeValueW, RegOverridePredefKey, RegCreateKeyW, RegEnumKeyW, RegOpenKeyW, CryptAcquireContextW, CryptReleaseContext, CryptDeriveKey, CryptDestroyKey, CryptSetHashParam, CryptGetHashParam, CryptExportKey, CryptImportKey, CryptDestroyHash, CryptHashData, CryptVerifySignatureW
SHELL32.dllSHGetMalloc, SHGetFolderPathW, SHBrowseForFolderW, ShellExecuteW, CommandLineToArgvW, SHGetSpecialFolderLocation, ShellExecuteExW, SHGetPathFromIDListW
ole32.dllCoCreateInstance, StringFromGUID2, CoCreateGuid, CreateItemMoniker, GetRunningObjectTable, CLSIDFromProgID, CoTaskMemAlloc, CoTaskMemRealloc, ProgIDFromCLSID, CoTaskMemFree, CoUninitialize, CoInitializeSecurity, CoInitialize
OLEAUT32.dllRegisterTypeLib, UnRegisterTypeLib, SetErrorInfo, LoadTypeLib, CreateErrorInfo, SysAllocStringLen, SysFreeString, SysReAllocStringLen, SysStringLen, SysAllocString, SysStringByteLen, SysAllocStringByteLen, VarBstrCat, VarBstrFromDate, VariantClear, VariantChangeType, GetErrorInfo, VarUI4FromStr, SystemTimeToVariantTime
RPCRT4.dllRpcStringFreeW, UuidCreate, UuidToStringW, UuidFromStringW
Language of compilation systemCountry where language is spokenMap
EnglishUnited States