Windows Analysis Report
EasyLogUSB+Installer.exe

Overview

General Information

Sample name: EasyLogUSB+Installer.exe
Analysis ID: 1501388
MD5: d3d4273692e34102b88c513ad1c10040
SHA1: 1b75e5c2644fbf075040df437b15d4d2c128c2cf
SHA256: cc2652dc33020fab609750a6f627e2f8e6597960b25f210981e62f5ad92f7d70
Infos:

Detection

Score: 6
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Compliance

Score: 45
Range: 0 - 100

Signatures

Checks for available system drives (often done to infect USB drives)
Creates driver files
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Launches processes in debugging mode, may be used to hinder debugging
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious Execution From GUID Like Folder Names
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

Compliance

barindex
Source: EasyLogUSB+Installer.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: EasyLogUSB+Installer.exe Static PE information: certificate valid
Source: C:\Windows\System32\msiexec.exe File opened: z:
Source: C:\Windows\System32\msiexec.exe File opened: x:
Source: C:\Windows\System32\msiexec.exe File opened: v:
Source: C:\Windows\System32\msiexec.exe File opened: t:
Source: C:\Windows\System32\msiexec.exe File opened: r:
Source: C:\Windows\System32\msiexec.exe File opened: p:
Source: C:\Windows\System32\msiexec.exe File opened: n:
Source: C:\Windows\System32\msiexec.exe File opened: l:
Source: C:\Windows\System32\msiexec.exe File opened: j:
Source: C:\Windows\System32\msiexec.exe File opened: h:
Source: C:\Windows\System32\msiexec.exe File opened: f:
Source: C:\Windows\System32\msiexec.exe File opened: b:
Source: C:\Windows\System32\msiexec.exe File opened: y:
Source: C:\Windows\System32\msiexec.exe File opened: w:
Source: C:\Windows\System32\msiexec.exe File opened: u:
Source: C:\Windows\System32\msiexec.exe File opened: s:
Source: C:\Windows\System32\msiexec.exe File opened: q:
Source: C:\Windows\System32\msiexec.exe File opened: o:
Source: C:\Windows\System32\msiexec.exe File opened: m:
Source: C:\Windows\System32\msiexec.exe File opened: k:
Source: C:\Windows\System32\msiexec.exe File opened: i:
Source: C:\Windows\System32\msiexec.exe File opened: g:
Source: C:\Windows\System32\msiexec.exe File opened: e:
Source: C:\Windows\System32\msiexec.exe File opened: c:
Source: C:\Windows\System32\msiexec.exe File opened: a:
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\x86\SiLib.sys
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\3eab17.msi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIADF5.tmp
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\SourceHash{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIAEF0.tmp
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\SiUSBXp.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exe
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exe
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exe
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\3eab19.msi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\3eab19.msi
Source: C:\Windows\System32\msiexec.exe File deleted: C:\Windows\Installer\MSIADF5.tmp
Source: EasyLogUSB+Installer.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engine Classification label: clean6.winEXE@11/44@0/0
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\Public\Desktop\EasyLog USB.lnk
Source: C:\Windows\System32\conhost.exe Mutant created: \BaseNamedObjects\Local\SM0:1992:120:WilError_03
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe File created: C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\
Source: EasyLogUSB+Installer.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe File read: C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\Setup.INI
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe File read: C:\Users\user\Desktop\EasyLogUSB+Installer.exe
Source: unknown Process created: C:\Users\user\Desktop\EasyLogUSB+Installer.exe "C:\Users\user\Desktop\EasyLogUSB+Installer.exe"
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Process created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe"
Source: unknown Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding C16B6E8B33D4F0B5DAD7A01ECF725878 C
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 27BDE6E8EAF7545954F65D95558F90D2
Source: C:\Windows\System32\msiexec.exe Process created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe"
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Process created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe"
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding C16B6E8B33D4F0B5DAD7A01ECF725878 C
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 27BDE6E8EAF7545954F65D95558F90D2
Source: C:\Windows\System32\msiexec.exe Process created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe"
Source: C:\Windows\SysWOW64\msiexec.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: msi.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: srpapi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: tsappcmp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: textinputframework.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wldp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: propsys.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: textshaping.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: netapi32.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wkscli.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msasn1.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: cryptsp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: rsaenh.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: cryptbase.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msisip.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: gpapi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mscoree.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msihnd.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: dwmapi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: pcacli.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: oleacc.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: windowscodecs.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: riched20.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: usp10.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msls31.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: srclient.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: spp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msisip.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: version.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: propsys.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: linkinfo.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ntshrui.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cscapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: acgenral.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: samcli.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: msacm32.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: version.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: aclayers.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: sfc.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: sfc_os.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe File written: C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\Setup.INI
Source: EasyLogUSB+Installer.exe Static PE information: certificate valid
Source: EasyLogUSB+Installer.exe Static file information: File size 19500624 > 1048576
Source: EasyLogUSB+Installer.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\ExportToExcel.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\SiUSBXp.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\x86\SiLib.sys Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\x64\SiUSBXp.sys Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\x86\SiUSBXp.sys Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exe Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe File created: C:\Users\user\AppData\Local\Temp\MSI96C5.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\EasyLogGraph.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\x64\SiLib.sys Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\CustomControls.dll Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe File created: C:\Users\user\AppData\Local\Temp\MSI9656.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\EasyLog USB\WPFToolkit.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\SiUSBXp.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyLog USB
Source: C:\Windows\System32\msiexec.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyLog USB\EasyLog USB.lnk
Source: C:\Windows\System32\msiexec.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyLog USB\EasyLogGraph.lnk
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\ExportToExcel.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\SiUSBXp.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x86\SiLib.sys Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x64\SiUSBXp.sys Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x86\SiUSBXp.sys Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exe Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI96C5.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\EasyLogGraph.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x64\SiLib.sys Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\CustomControls.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\WPFToolkit.dll Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI9656.tmp Jump to dropped file
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exe File Volume queried: C:\Users\user\AppData\Local\Temp FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe Process information queried: ProcessInformation
Source: C:\Windows\System32\msiexec.exe Process created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe"
Source: C:\Windows\SysWOW64\msiexec.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation
⊘No contacted IP infos