Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_0024D9D5 __EH_prolog3_GS,GetFullPathNameW,PathIsUNCW,GetVolumeInformationW,CharUpperW,FindFirstFileW,FindClose, |
0_2_0024D9D5 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0024D9D5 __EH_prolog3_GS,GetFullPathNameW,PathIsUNCW,GetVolumeInformationW,CharUpperW,FindFirstFileW,FindClose, |
3_2_0024D9D5 |
Source: startswinstall.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: startswinstall.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: startswinstall.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: startswinstall.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: startswinstall.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: startswinstall.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: startswinstall.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: startswinstall.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: startswinstall.exe |
String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: startswinstall.exe |
String found in binary or memory: http://ocsp.digicert.com0 |
Source: startswinstall.exe |
String found in binary or memory: http://ocsp.digicert.com0A |
Source: startswinstall.exe |
String found in binary or memory: http://ocsp.digicert.com0C |
Source: startswinstall.exe |
String found in binary or memory: http://ocsp.digicert.com0X |
Source: startswinstall.exe |
String found in binary or memory: http://www.digicert.com/CPS0 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_00270152 MessageBeep,SendMessageW,SendMessageW,SendMessageW,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW, |
0_2_00270152 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_00270152 MessageBeep,SendMessageW,SendMessageW,SendMessageW,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW, |
3_2_00270152 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_0039C131 |
0_2_0039C131 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_0039E317 |
0_2_0039E317 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_002773F5 |
0_2_002773F5 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_0038F500 |
0_2_0038F500 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_002655F4 |
0_2_002655F4 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_0039DB1D |
0_2_0039DB1D |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_002B0BD0 |
0_2_002B0BD0 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_0039DC3D |
0_2_0039DC3D |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_00385CF7 |
0_2_00385CF7 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_00296DB1 |
0_2_00296DB1 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_00385F5C |
0_2_00385F5C |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_00282F9D |
0_2_00282F9D |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_0025AF9F |
0_2_0025AF9F |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0039C131 |
3_2_0039C131 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0039E317 |
3_2_0039E317 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_002773F5 |
3_2_002773F5 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0038F500 |
3_2_0038F500 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_002655F4 |
3_2_002655F4 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0039DB1D |
3_2_0039DB1D |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_002B0BD0 |
3_2_002B0BD0 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0039DC3D |
3_2_0039DC3D |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_00385CF7 |
3_2_00385CF7 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_00296DB1 |
3_2_00296DB1 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_00385F5C |
3_2_00385F5C |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_00282F9D |
3_2_00282F9D |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0025AF9F |
3_2_0025AF9F |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: String function: 0037FC60 appears 91 times |
|
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: String function: 0037F9B4 appears 80 times |
|
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: String function: 0037F980 appears 229 times |
|
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3712:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6180:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5564:120:WilError_03 |
Source: startswinstall.exe |
String found in binary or memory: <StopOnError>0</StopOnError> |
Source: startswinstall.exe |
String found in binary or memory: <StopOnError>0</StopOnError> |
Source: startswinstall.exe |
String found in binary or memory: <StopOnCancel>0</StopOnCancel> |
Source: startswinstall.exe |
String found in binary or memory: <StopOnCancel>0</StopOnCancel> |
Source: unknown |
Process created: C:\Users\user\Desktop\startswinstall.exe "C:\Users\user\Desktop\startswinstall.exe" -install |
Source: C:\Users\user\Desktop\startswinstall.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: unknown |
Process created: C:\Users\user\Desktop\startswinstall.exe "C:\Users\user\Desktop\startswinstall.exe" /install |
Source: C:\Users\user\Desktop\startswinstall.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: unknown |
Process created: C:\Users\user\Desktop\startswinstall.exe "C:\Users\user\Desktop\startswinstall.exe" /load |
Source: C:\Users\user\Desktop\startswinstall.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: msimg32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: oleacc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: ndfapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wdi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: duser.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: atlthunk.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: msimg32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: oleacc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: ndfapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wdi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: duser.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: atlthunk.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: msimg32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: oleacc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: ndfapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wdi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: duser.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: atlthunk.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\startswinstall.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: startswinstall.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: startswinstall.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: startswinstall.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: startswinstall.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: startswinstall.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: startswinstall.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: startswinstall.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: startswinstall.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: startswinstall.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: startswinstall.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: startswinstall.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_00298EA9 SetRectEmpty,RedrawWindow,ReleaseCapture,SetCapture,ReleaseCapture,SetCapture,SendMessageW,UpdateWindow,SendMessageW,IsWindow,IsIconic,IsZoomed,IsWindow,UpdateWindow, |
0_2_00298EA9 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0029852C __EH_prolog3_GS,GetParent,GetParent,UpdateWindow,SetCursor,GetAsyncKeyState,InvalidateRect,InflateRect,RedrawWindow,InvalidateRect,InflateRect,UpdateWindow,InflateRect,SetCapture,SetCursor,IsWindow,GetCursorPos,ScreenToClient,PtInRect,RedrawWindow,GetParent,GetParent,RedrawWindow,RedrawWindow,GetParent,GetParent,GetParent,InvalidateRect,UpdateWindow,UpdateWindow,NotifyWinEvent,NotifyWinEvent,SetCapture,RedrawWindow,SetRectEmpty,RedrawWindow,ReleaseCapture,SetCapture,ReleaseCapture,SetCapture,SendMessageW,UpdateWindow,SendMessageW,IsWindow,IsIconic,IsZoomed,IsWindow,UpdateWindow, |
3_2_0029852C |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_0024D9D5 __EH_prolog3_GS,GetFullPathNameW,PathIsUNCW,GetVolumeInformationW,CharUpperW,FindFirstFileW,FindClose, |
0_2_0024D9D5 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0024D9D5 __EH_prolog3_GS,GetFullPathNameW,PathIsUNCW,GetVolumeInformationW,CharUpperW,FindFirstFileW,FindClose, |
3_2_0024D9D5 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_00391D0F mov eax, dword ptr fs:[00000030h] |
0_2_00391D0F |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_00397EA5 mov eax, dword ptr fs:[00000030h] |
0_2_00397EA5 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_00391D0F mov eax, dword ptr fs:[00000030h] |
3_2_00391D0F |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_00397EA5 mov eax, dword ptr fs:[00000030h] |
3_2_00397EA5 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_0037FA5C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_0037FA5C |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 0_2_00386B83 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_00386B83 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_0037FA5C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
3_2_0037FA5C |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: 3_2_00386B83 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
3_2_00386B83 |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: GetModuleHandleW,GetProcAddress,EncodePointer,DecodePointer,GetLocaleInfoW, |
0_2_00250F0A |
Source: C:\Users\user\Desktop\startswinstall.exe |
Code function: GetModuleHandleW,GetProcAddress,EncodePointer,DecodePointer,GetLocaleInfoW, |
3_2_00250F0A |