Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
b2 ControlCenter Setup V3.75.exe

Overview

General Information

Sample name:b2 ControlCenter Setup V3.75.exe
Analysis ID:1533000
MD5:f02023e1e165fb92adaab5bf1ef98ed9
SHA1:9de491da46b50716d1b8164221c9b84a111fdfc2
SHA256:2a92ac98ae89f214cd10b1ca5eb26316bb588f73d5e0a2642c1768712ffb0aad
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Injects code into the Windows Explorer (explorer.exe)
Writes to foreign memory regions
Allocates memory with a write watch (potentially for evading sandboxes)
Checks for available system drives (often done to infect USB drives)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64_ra
  • b2 ControlCenter Setup V3.75.exe (PID: 6952 cmdline: "C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe" MD5: F02023E1E165FB92ADAAB5BF1EF98ED9)
    • b2 ControlCenter Setup V3.75.exe (PID: 7024 cmdline: "C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe" /q"C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe" /tempdisk1folder"C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}" /IS_temp MD5: F02023E1E165FB92ADAAB5BF1EF98ED9)
      • msiexec.exe (PID: 6660 cmdline: "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Downloaded Installations\{B1B7EEAC-19DF-4A66-92D0-4A9FA0D4FD78}\b2 ControlCenter.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="b2 ControlCenter Setup V3.75.exe" MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • explorer.exe (PID: 1576 cmdline: C:\Windows\system32\explorer.exe MD5: DD6597597673F72E10C9DE7901FBA0A8)
  • msiexec.exe (PID: 6744 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 6732 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 3D0F18109D3614DB0081A4658BA6B54A C MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • ControlCenter.App.exe (PID: 6880 cmdline: "C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe" MD5: 403CD2799955C678726B5F04FA891B25)
    • msiexec.exe (PID: 5688 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 4A9F0DD437EA1637B8442FC35E2B2DD0 MD5: 9D09DC1EDA745A5F87553048E57620CF)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Windows\System32\msiexec.exeFile opened: z:
Source: C:\Windows\System32\msiexec.exeFile opened: x:
Source: C:\Windows\System32\msiexec.exeFile opened: v:
Source: C:\Windows\System32\msiexec.exeFile opened: t:
Source: C:\Windows\System32\msiexec.exeFile opened: r:
Source: C:\Windows\System32\msiexec.exeFile opened: p:
Source: C:\Windows\System32\msiexec.exeFile opened: n:
Source: C:\Windows\System32\msiexec.exeFile opened: l:
Source: C:\Windows\System32\msiexec.exeFile opened: j:
Source: C:\Windows\System32\msiexec.exeFile opened: h:
Source: C:\Windows\System32\msiexec.exeFile opened: f:
Source: C:\Windows\System32\msiexec.exeFile opened: b:
Source: C:\Windows\System32\msiexec.exeFile opened: y:
Source: C:\Windows\System32\msiexec.exeFile opened: w:
Source: C:\Windows\System32\msiexec.exeFile opened: u:
Source: C:\Windows\System32\msiexec.exeFile opened: s:
Source: C:\Windows\System32\msiexec.exeFile opened: q:
Source: C:\Windows\System32\msiexec.exeFile opened: o:
Source: C:\Windows\System32\msiexec.exeFile opened: m:
Source: C:\Windows\System32\msiexec.exeFile opened: k:
Source: C:\Windows\System32\msiexec.exeFile opened: i:
Source: C:\Windows\System32\msiexec.exeFile opened: g:
Source: C:\Windows\System32\msiexec.exeFile opened: e:
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: c:
Source: C:\Windows\System32\msiexec.exeFile opened: a:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\600481.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{D7F46775-46B0-4E89-8069-65CC2FA60046}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI77F.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI7ED.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\600483.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\600483.msi
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSI77F.tmp
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: mal48.evad.winEXE@14/69@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeFile created: C:\Users\user\AppData\Local\Downloaded Installations
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeMutant created: NULL
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeFile created: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess created: C:\Windows\SysWOW64\explorer.exe
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess created: C:\Windows\SysWOW64\explorer.exe
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeFile read: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\_ISMSIDEL.INI
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeFile read: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe
Source: unknownProcess created: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe "C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe"
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeProcess created: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe "C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe" /q"C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe" /tempdisk1folder"C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}" /IS_temp
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Downloaded Installations\{B1B7EEAC-19DF-4A66-92D0-4A9FA0D4FD78}\b2 ControlCenter.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="b2 ControlCenter Setup V3.75.exe"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 3D0F18109D3614DB0081A4658BA6B54A C
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeProcess created: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe "C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe" /q"C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe" /tempdisk1folder"C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}" /IS_temp
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 4A9F0DD437EA1637B8442FC35E2B2DD0
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe "C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe"
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Downloaded Installations\{B1B7EEAC-19DF-4A66-92D0-4A9FA0D4FD78}\b2 ControlCenter.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="b2 ControlCenter Setup V3.75.exe"
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\system32\explorer.exe
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 3D0F18109D3614DB0081A4658BA6B54A C
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 4A9F0DD437EA1637B8442FC35E2B2DD0
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe "C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe"
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\system32\explorer.exe
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeSection loaded: apphelp.dll
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: msi.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: srpapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textinputframework.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textshaping.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wkscli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msihnd.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: dwmapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: pcacli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: oleacc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windowscodecs.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: linkinfo.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntshrui.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: srvcli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cscapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: edputil.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: urlmon.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iertutil.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: srvcli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: appresolver.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: bcp47langs.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: slc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: userenv.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sppc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: mscoree.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: version.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: uxtheme.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: dwrite.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: msvcp140_clr0400.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: dwmapi.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: d3d9.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: d3d10warp.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: urlmon.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: iertutil.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: srvcli.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: windowscodecs.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: mscms.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: coloradapterclient.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: windowscodecsext.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: wtsapi32.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: winsta.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: powrprof.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: umpdc.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: textshaping.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: dataexchange.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: d3d11.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: dcomp.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: dxgi.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: twinapi.appcore.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: resourcepolicyclient.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: dxcore.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: textinputframework.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: coremessaging.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: msctfui.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: uiautomationcore.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: propsys.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: d3dcompiler_47.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: sspicli.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: windows.applicationmodel.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: amsi.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: wsock32.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: bluetoothapis.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: devobj.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: 32feetwidcomm.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: bssdk.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: bluetoothapis.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: devobj.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: 32feetwidcomm.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeSection loaded: bssdk.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: aepic.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: twinapi.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: userenv.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: powrprof.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: dxgi.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: propsys.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: urlmon.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: wtsapi32.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: wininet.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: dwmapi.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: twinapi.appcore.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: cryptsp.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: iertutil.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: srvcli.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\explorer.exeSection loaded: umpdc.dll
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InprocServer32
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeFile written: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\_ISMSIDEL.INI
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll
Source: b2 ControlCenter Setup V3.75.exeStatic file information: File size 16740243 > 1048576
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: b2 ControlCenter Setup V3.75.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.DocumentObjectModel-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Teslab.Louserzation.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.Visa.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.RemoteControl.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Installer\{D7F46775-46B0-4E89-8069-65CC2FA60046}\NewShortcut1_0E96F1A19A774C13AC5791AB896F9F0F.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\DriverPackage.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.Core.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\MSI180A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.ServiceArea.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.LouserzationProvider.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.RtfRendering-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Abt.Controls.SciChart.Wpf.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\MSIF425.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Ivi.Visa.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Charting.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\IPManager.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.Devices.Common.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.Rendering-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Teslab.Wpf.Extensions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NGettext.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\InTheHand.Net.Personal.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Teslab.StateMachine.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI77F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Common.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Installer\{D7F46775-46B0-4E89-8069-65CC2FA60046}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeFile created: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\PdfSharp-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\PdfSharp.Charting-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.VisaNS.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.HVA2G.Generic.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.License.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Core.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Xceed.Wpf.Toolkit.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI77F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\b2 electronic GmbH
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\b2 electronic GmbH\b2 ControlCenter
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\b2 electronic GmbH\b2 ControlCenter\ControlCenter.lnk
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeMemory allocated: 21932670000 memory reserve | memory write watch
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeMemory allocated: 2194C020000 memory reserve | memory write watch
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeThread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeWindow / User API: threadDelayed 488
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.DocumentObjectModel-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Teslab.Louserzation.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.Visa.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.RemoteControl.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Microsoft\Installer\{D7F46775-46B0-4E89-8069-65CC2FA60046}\NewShortcut1_0E96F1A19A774C13AC5791AB896F9F0F.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\DriverPackage.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.Core.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI180A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.ServiceArea.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.LouserzationProvider.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.RtfRendering-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Abt.Controls.SciChart.Wpf.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSIF425.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Ivi.Visa.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Charting.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\IPManager.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.Devices.Common.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.Rendering-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Teslab.Wpf.Extensions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NGettext.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\InTheHand.Net.Personal.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Teslab.StateMachine.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Common.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI77F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Microsoft\Installer\{D7F46775-46B0-4E89-8069-65CC2FA60046}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\PdfSharp-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\PdfSharp.Charting-WPF.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.VisaNS.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.HVA2G.Generic.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.License.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Core.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Xceed.Wpf.Toolkit.dllJump to dropped file
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe TID: 7160Thread sleep count: 488 > 30
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe TID: 7160Thread sleep time: -240000s >= -30000s
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe TID: 7160Thread sleep time: -60000s >= -30000s
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe TID: 7160Thread sleep time: -1680000s >= -30000s
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe TID: 6540Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe TID: 7160Thread sleep time: -60000s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeFile Volume queried: C:\Users\user\AppData\Local\Temp FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeThread delayed: delay time: 60000
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeThread delayed: delay time: 60000
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeThread delayed: delay time: 60000
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeThread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeThread delayed: delay time: 60000
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeProcess token adjusted: Debug
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeMemory allocated: page read and write | page guard

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeMemory written: PID: 1576 base: 2E7EF00 value: 00
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeMemory written: C:\Windows\SysWOW64\explorer.exe base: 2E7EF00
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe "C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe"
Source: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exeProcess created: C:\Windows\SysWOW64\explorer.exe C:\Windows\system32\explorer.exe
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeProcess created: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe "c:\users\user\appdata\local\temp\{12bebbfb-a371-46b3-a0d0-50a2008b50c2}\b2 controlcenter setup v3.75.exe" /q"c:\users\user\desktop\b2 controlcenter setup v3.75.exe" /tempdisk1folder"c:\users\user\appdata\local\temp\{12bebbfb-a371-46b3-a0d0-50a2008b50c2}" /is_temp
Source: C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exeProcess created: C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe "c:\users\user\appdata\local\temp\{12bebbfb-a371-46b3-a0d0-50a2008b50c2}\b2 controlcenter setup v3.75.exe" /q"c:\users\user\desktop\b2 controlcenter setup v3.75.exe" /tempdisk1folder"c:\users\user\appdata\local\temp\{12bebbfb-a371-46b3-a0d0-50a2008b50c2}" /is_temp
Source: C:\Windows\SysWOW64\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Common.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.Core.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.Devices.Common.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Core.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.License.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Teslab.StateMachine.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.HVA2G.Generic.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.LouserzationProvider.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NGettext.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Abt.Controls.SciChart.Wpf.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Charting.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.DocumentObjectModel-WPF.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.RemoteControl.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.ServiceArea.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.Devices.winmd VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.Foundation.winmd VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.InteropServices.WindowsRuntime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.InteropServices.WindowsRuntime.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\DriverPackage.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\InTheHand.Net.Personal.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\IPManager.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Ivi.Visa.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.Rendering-WPF.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\PdfSharp-WPF.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.RtfRendering-WPF.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.Visa.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.VisaNS.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.VisaNS.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.VisaNS.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\PdfSharp.Charting-WPF.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Teslab.Wpf.Extensions.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Xceed.Wpf.Toolkit.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXmlLinq\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXmlLinq.dll VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
1
Command and Scripting Interpreter
1
Registry Run Keys / Startup Folder
211
Process Injection
22
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Registry Run Keys / Startup Folder
1
Disable or Modify Tools
LSASS Memory32
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
32
Virtualization/Sandbox Evasion
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook211
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets2
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
File Deletion
Cached Domain Credentials13
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
SourceDetectionScannerLabelLink
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Abt.Controls.SciChart.Wpf.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Abt.Controls.SciChart.Wpf.dll0%VirustotalBrowse
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.LouserzationProvider.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.LouserzationProvider.dll0%VirustotalBrowse
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\IPManager.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\IPManager.dll0%VirustotalBrowse
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\InTheHand.Net.Personal.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\InTheHand.Net.Personal.dll0%VirustotalBrowse
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Ivi.Visa.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\Ivi.Visa.dll0%VirustotalBrowse
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.DocumentObjectModel-WPF.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.DocumentObjectModel-WPF.dll0%VirustotalBrowse
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.Rendering-WPF.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.Rendering-WPF.dll0%VirustotalBrowse
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.RtfRendering-WPF.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\MigraDoc.RtfRendering-WPF.dll0%VirustotalBrowse
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NGettext.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NGettext.dll0%VirustotalBrowse
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.Visa.dll0%ReversingLabs
C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\NationalInstruments.Visa.dll0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1533000
Start date and time:2024-10-14 09:36:04 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:17
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
Analysis Mode:stream
Analysis stop reason:Timeout
Sample name:b2 ControlCenter Setup V3.75.exe
Detection:MAL
Classification:mal48.evad.winEXE@14/69@0/0
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): dllhost.exe
  • Excluded domains from analysis (whitelisted): fs.microsoft.com
  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:modified
Size (bytes):49339
Entropy (8bit):5.791509537136401
Encrypted:false
SSDEEP:
MD5:23EE1A77543CD0FD00F9D614D6EEAA66
SHA1:644FEAAC4F0ABD656DA629872BE472ABE0083CF3
SHA-256:B53628C4D70C30908123951BB9DE569527629E99A18939B44419F4579CB3E99B
SHA-512:31FA0613B5DF676F96366E64A8AF86ECC847EAB83A020BD462FA0D3AC3D1D9A9B6D6381D4AA8F99223AD370A61AFE04F2279FBA7375F9381E5FFB7108ABAB437
Malicious:false
Reputation:unknown
Preview:...@IXOS.@.....@..NY.@.....@.....@.....@.....@.....@......&.{D7F46775-46B0-4E89-8069-65CC2FA60046}..b2 ControlCenter..b2 ControlCenter.msi.@.....@..K..@.....@......ARPPRODUCTICON.exe..&.{B1B7EEAC-19DF-4A66-92D0-4A9FA0D4FD78}.....@.....@.....@.....@.......@.....@.....@.......@......b2 ControlCenter......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{F4E0226A-1877-4C25-BF3C-9DA3A77E9288}&.{D7F46775-46B0-4E89-8069-65CC2FA60046}.@......&.{3642024A-7A59-4499-8599-6F2D0C684D04}&.{D7F46775-46B0-4E89-8069-65CC2FA60046}.@......&.{4BD8BC03-7008-4D7A-B432-05B41111BC16}&.{D7F46775-46B0-4E89-8069-65CC2FA60046}.@......&.{9EBEE10F-D4FE-4567-B4EF-D65EE4AF68A0}&.{D7F46775-46B0-4E89-8069-65CC2FA60046}.@......&.{600D3D94-E9D0-4E99-A1C7-47C704A2F15A}&.{D7F46775-46B0-4E89-8069-65CC2FA60046}.@......&.{2E20587B-2AF4-49A3-889C-80C4BB7D3951}&.{D7F46775-46B0-4E89-8069-65CC2FA60046}.@......&.{B17B2D41-1AE9-4C1C-B2B9
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):1310720
Entropy (8bit):6.2729854395546285
Encrypted:false
SSDEEP:
MD5:F8EDA0480C2082CDD222810532B0844D
SHA1:674DCEBEA3CE6A53F1802BEDA983274FE3D5EC50
SHA-256:6463208203BADD73611D165141E156B649F374702A74E6594B1994B072F2E672
SHA-512:490263FAB6E7A1530AE6486EC6D25322A38E404786B1E486AA09988C1094B2181672A07D9F8942D547248046CF2192AA2FBB1571ABBE39120379DFC177315CE3
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......U...........!..................... ........@.. .......................@.......X....@.....................................W.... ..............................$e............................................... ............... ..H............text........ ...................... ..`.reloc..............................@..B.rsrc........ ......................@..@........................H........e..............A..."...d......................................6.(m...(.....*...0...........4................%.L...(..............%.M...(..............%.N...(..............%.O...(..............%.P...(..............%.Q...(..............%.R...(..............%.S...(..............%.T...(...............%.U...(...............%.V...(...............%.W...(...............%.X...(...............%.Y...(...............%.Z...(...............%.[...(...............%.\...(...........
Process:C:\Windows\System32\msiexec.exe
File Type:XML 1.0 document, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):927169
Entropy (8bit):4.604107843327761
Encrypted:false
SSDEEP:
MD5:E35046D7E030839DA9B711B28FCF86FB
SHA1:DBA6CAF4B5D29BC9435BD021A796F7998690BC7F
SHA-256:7CE3766D37BC26A60E21DFFC90D48EB1D45B76188E08EC5F38A764F63F0DBF31
SHA-512:382980085D58AA3B2BEEFA8698B362F73A2824090D99903C3B8C44BDE55866049100879A94EB8B222D3CF149A52635350971290EE29D31035424E20EA6C35427
Malicious:false
Reputation:unknown
Preview:<?xml version="1.0"?>..<doc>.. <assembly>.. <name>Abt.Controls.SciChart.Wpf</name>.. </assembly>.. <members>.. <member name="T:Abt.Controls.SciChart.AxisAlignmentToHorizontalAlignmentConverter">.. <summary>.. Converts input <see cref="T:Abt.Controls.SciChart.AxisAlignment"/> to <see cref="T:System.Windows.FlowDirection"/>, is such a way that Left becomes RightToLeft and Right becomes LeftToRight.. </summary>.. </member>.. <member name="M:Abt.Controls.SciChart.BandSeriesInfoToYValueConverter.Convert(System.Object,System.Type,System.Object,System.Globalization.CultureInfo)">.. <summary>.. Converts a value... </summary>.. <param name="value">The value produced by the binding source.</param>.. <param name="targetType">The type of the binding target property.</param>.. <param name="parameter">The converter parameter to use.</param>.. <param name=
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):62976
Entropy (8bit):5.690625386053806
Encrypted:false
SSDEEP:
MD5:6CB28EECEBDCFAE515ACC5717C021D82
SHA1:87974E39D411F652E536C5E125B7D12ABBD9CB3C
SHA-256:1B88DF125CEE5FF7A299ECE8B2723DEA81211B2318904C0D9BFEDEA8B04BD5CC
SHA-512:9180F5C7BCD113F0B37705242838398911F872DF1BD6D014F77E08ADDF54F988FEBE3F496EC4F4DD160A4E506E0244138915158027F0A811A885D44E620D040F
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c.........." ..0.............B.... ... ....... .......................`............`.....................................O.... .......................@....................................................... ............... ..H............text...H.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B................$.......H.......d....y..........8.................................................{....*"..}....*..{....*"..}....*F.~....(....uA...*6.~.....(....*Z.~....(....u.........*J.~..........(....*Z.~....(....u.........*J.~..........(....*Z.~....(....u.........*J.~..........(....*Z.~....(....u.........*J.~..........(....*Z.~....(....u.........*J.~..........(....*Z.~....(....u.........*J.~..........(....*F.~....(....uA...*6.~.....(....*Z.~....(....u.........*J.~..........(....*.0..........r...
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):4404224
Entropy (8bit):7.489236035899555
Encrypted:false
SSDEEP:
MD5:8D286EF833EA016E002A5DA8A0C5F03D
SHA1:6EA6F967E55B927CAA3132DFB78B9F9F7E76F40C
SHA-256:0CEFBBE9B9AE3C218AC4FCBE71DF68C5B326750C27BCADD6D7466DD83D65E346
SHA-512:DF42926DC5F872E8B384D827FD51041E335C275AE8E8B75D5E599FF5604C48C6AD30087680A697346E8C5CE46C7B2649EF2A00416D6F492FE7CCDA6AB3FB056C
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c.........." ..0..*C..........IC.. ...`C...... ........................C...........`..................................IC.O....`C.t.....................C.....PHC.............................................. ............... ..H............text....)C.. ...*C................. ..`.rsrc...t....`C......,C.............@..@.reloc........C......2C.............@..B.................IC.....H............P..........p....mA.........................................>. 4......( ...*2......o!...*:........o"...*.0..,........o#...r...p $...........%...%....o$...t....*&...o%...*..(&...*...}......}.....('....s(...}....*...}......}.....('....s(...}......}....*..{....*F.s....t....}....*V.{....,..{....()...&*..0..R........,N.{......ox......o.....o*.....+......(7...(6...o+.....X..j.n2...6....o,...('...*".. `...*..{....*r..}.....(5...,..{.....oV...*..{....*"..}....*..{....*N.r
Process:C:\Windows\System32\msiexec.exe
File Type:XML 1.0 document, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):3239
Entropy (8bit):4.800019939763942
Encrypted:false
SSDEEP:
MD5:09E408AA3F879A3C6C8F958214C88CF1
SHA1:28A6E8D1A51405920540AFA317063B7EF2939DD4
SHA-256:ACE2378A6901D109A4228468CD0DF97F8D59FCCE7C79DABAB0395F2BB966BC03
SHA-512:3C9423B9AC0026174870D4A6175F6DEBA95D2B65CA6EA8747FFF91F1B732268ED5310243713391FBC2769A2AEA09FA9C3949D193ABF70C097FFF737717372589
Malicious:false
Reputation:unknown
Preview:<?xml version="1.0"?>..<configuration>.. <configSections>.. <sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089">.. <section name="B2.ControlCenter.Properties.B2CoreSettings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false"/>.. <section name="B2.ControlCenter.UI.Properties.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false"/>.. </sectionGroup>.. </configSections>.. <userSettings>.. <B2.ControlCenter.Properties.B2CoreSettings>.. <setting name="IsFirstApplicationRun" serializeAs="String">.. <value>True</value>.. </setting>.. <setting name="ReportsLocalPath" s
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):14336
Entropy (8bit):4.93189202892329
Encrypted:false
SSDEEP:
MD5:AAA4651C3449E7C9CCCCE1D273EA78DD
SHA1:0EE2BAB8384AC6684CEDFDCA6E2BA46449EF05C5
SHA-256:A4627BED9321A6765BAB722D576D4C07735F24A025153253B503683C33737A61
SHA-512:A2CB44ACD9758A5736ECD1EB36465571E2A9E252314775D2308D6D49DEDA0B14B43BA1C91F3A6828B6EC0BD0A9C1BC6B223DBDD3AC9FEAB9942FEE1D08A288E6
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c.........." ..0............."M... ...`....... ....................................`..................................L..O....`..`............................K............................................... ............... ..H............text...(-... ...................... ..`.rsrc...`....`.......0..............@..@.reloc...............6..............@..B.................M......H.......`)..8"...........................................................*..(....*...0..w........r...p(....o........i..r...pr4..ps....z....o....Q....o....r...p(.......o....r...p(.......o....r...p(.......o....(....Q*..0..z........r...p(....o.....s.......i.2...i.1.rF..pr4..ps....z....o....Q.~....Q..+#..1..r...po....&....o....o....&..X....i2...o....Q*...0...............(.......(....*..0...............(.......(....*..0...........r...p.(........(.......(....*...0..3..........o....
Process:C:\Windows\System32\msiexec.exe
File Type:XML 1.0 document, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):1180
Entropy (8bit):4.837635969266507
Encrypted:false
SSDEEP:
MD5:BF8770F62243495C66EBC8C2B127FA4F
SHA1:0E1362DF25AD72D74275EE562CBDEC1CCC48933D
SHA-256:7DD113885D80F953488D2FD533831EE8954054B58C15C2C96E56FF01A804E022
SHA-512:1C8FF06F8733AAFE230B2EA1CBC589A637030AE037B5D969BC9849EC34AA1E4107EC1337CECB154B3AFF6D767549BAC017127CAF80256A82DB70B72EAC1AD06B
Malicious:false
Reputation:unknown
Preview:<?xml version="1.0"?>..<configuration>.. <configSections>.. <sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089">.. <section name="B2.ControlCenter.Properties.B2CoreSettings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false"/>.. </sectionGroup>.. </configSections>.. <userSettings>.. <B2.ControlCenter.Properties.B2CoreSettings>.. <setting name="IsFirstApplicationRun" serializeAs="String">.. <value>True</value>.. </setting>.. <setting name="ReportsLocalPath" serializeAs="String">.. <value/>.. </setting>.. <setting name="SequencesLocalPath" serializeAs="String">.. <value/>.. </setting>.. </B2.C
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):989184
Entropy (8bit):6.501271268160047
Encrypted:false
SSDEEP:
MD5:AC599583A06801316B8A846E5252D3E1
SHA1:2AD87F2F5EAAC9C0D727E47AE540677D2ABD6B34
SHA-256:F098E190DD2E26063DB03436B5C3248C5DCC5EAB6BDD120325104550BE5AACFE
SHA-512:417EEDF0B0A58535D22B96B6DC91CBF7B711758BFD922FB5CE7589C36BCC01431000DCBFED552EA84D9327655FDAC90E9C6CFDA847916B52ADA609D54636CB92
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c.........." ..0.............:-... ...@....... ....................................`..................................,..O....@.......................`.......+............................................... ............... ..H............text...@.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................-......H......................p...@b..........................................R.(.....(......}....*..{.....{....o....o....o......s....(.....(....*.0..$........{....,.*..}....r...p.s.......(....*.0..\.........YE............3...+>..t....}....*..t....}.....{...........s....o....*..t....}....*..}....*..( ...*.~....-.r...p.....(!...o"...s#........~....*.~....*.......*.~....*..($...*Vs....(%...t.........*..{....*.0............}.....r...po.....{....,u.{....o&...,h.{....o&...o'...,V.{....o
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):116736
Entropy (8bit):6.0521299823542405
Encrypted:false
SSDEEP:
MD5:6D85EC59CD296D3D54CE947871F61011
SHA1:799767B0ACEF6C0B6573B84B350F8E6CF44D8CAE
SHA-256:EE8A17F4189BD8A3668E19BFEE91F914F36096B69BD3D165E38598D40E7BE4E6
SHA-512:56D2289DF49021D7A74BC6FE952A7459300B87A056EF4F742FFCF79FC6DEF6DCE43AB938A2B41EA5C0F2D984F3FE27F83472737BC115DB53B4E6D736E69050A1
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c.........." ..0.................. ........... ....................... ............`.....................................O.......(...........................\................................................ ............... ..H............text....... ...................... ..`.rsrc...(...........................@..@.reloc..............................@..B........................H........... ............-..............................................6.(.....(....*..o....r...p(....,..{....o....,..(....*....0..U.......s9......}......{....o....o.......:...s....(...+}.....{....-.*.(.......;...s....o....*...(....u....}.....{...........s....o ...*..0..$........{....,.*..}....r...p.s!......("...*.0............YE............'...4...A...N...+Y.t...........s#...o$...*..t....}....*..t....}....*..t....}....*..t....}....*..t....}....*..}....*.s.........s.........
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):1829888
Entropy (8bit):6.240725805389154
Encrypted:false
SSDEEP:
MD5:36911A0FB8C4E111847428308DDC3EB0
SHA1:4D412CE813CD80B0C2298F605494E7321FBFDF87
SHA-256:9623D91B7374DFE183778C5960FAA08C66E41CB4EAF26B51A7BFC7EFF2768DA8
SHA-512:6EAD19558FB29FE415752C6B14FAA3DA9851C4837DC08E6D9ACB69828816DB651E345BA1253796B0DA49FD555C6F045D270FC282B99C8E543214A798105BB081
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..._..c.........." ..0.............>.... ... ....... .......................`............`.....................................O.... .......................@....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B................ .......H........V..xm...............5............................................{....*R.r...p.|.....(...+&*..{....*R.r'..p.|.....(...+&*...0..v........(.....(....o$...-..(.....(....o%...+).(.....(.....(....o&....(....o'....Yo(....(....o'.....1..(.....o)....~*...(....*...0..s..........(....(+...,!.(....o'....0..+..(....o'....Y.+..(.....(....o&.....-...X+...Y...2 ..(....o'.../...(.....o,...(....*v.s-...}.....rS..p}.....(....*6.(/....(....*2.{....o0...*.0...........o1.....@....(2...._
Process:C:\Windows\System32\msiexec.exe
File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
Category:dropped
Size (bytes):1791
Entropy (8bit):4.684342590063428
Encrypted:false
SSDEEP:
MD5:0BF11EF43E0754359CD6D8299C343EB1
SHA1:71409538A508204F8D70C070925770AFB7E361C5
SHA-256:1CB146723C194DE948131E2817D1C3414C1413C09DF9B01475A782AED03ED2F6
SHA-512:61D589CA47F7EF12FC9AB0387906711BD2FBD85DD4ED206F68BA1503ECBCA887FBF728818F3523688FBDFBB2C1EC86AF2B12B8AE865AF6A075914DA5421F761A
Malicious:false
Reputation:unknown
Preview:.<?xml version="1.0" encoding="utf-8" ?>..<configuration>.. <configSections>.. <sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" >.. <section name="B2.ControlCenter.UI.Service.Properties.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false" />.. </sectionGroup>.. </configSections>.. <userSettings>.. <B2.ControlCenter.UI.Service.Properties.Settings>.. <setting name="PDC_USBConnectString" serializeAs="String">.. <value>USB0::0x1AB1::0x04B1::</value>.. </setting>.. <setting name="PDC_OscilloscopeSerialNo" serializeAs="String">.. <value>DS4A162850296</value>.. </setting>.. <setting name="ScopePath" serializeAs="Strin
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):65024
Entropy (8bit):5.731304699874705
Encrypted:false
SSDEEP:
MD5:D8AD3578D352A064F7FC19596F9B8BFA
SHA1:AEE9B2DB7F0D0942BB567078EF49EEDFA72E245E
SHA-256:25248F81FCB1688A0D6EB48C6CFBE697263105DA6A6C2C25699D07787E1CAF97
SHA-512:F613CE8A3250FBBF46C3C967B202D5A410B094AB1860659AB7DBC6C4724E514FC21F903D32587D7149FD0C0BC0E06C8BAF8C75CA429DE9EEC26966B0C718953A
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c.........." ..0.............B.... ... ....... .......................`............`.....................................O.... .......................@....................................................... ............... ..H............text...H.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B................$.......H.......Lq..l.............................................................{ ...*"..o!...*2.("........*6.......(#...*..(8...*:.(8.....o!...*..0..i........{ ........,..{ ..............o$...,.*..} ....r...po4....o%....{ ........,..{ .........%..&...s'...o(...*.*..0............o*......((....*....................0....................o!....(+...*..{)...*N..})....r...po*...*r..}+....(,.....}).....(-...*..0...........{....,).{....u......,...%../...s0...o1.....}.....(2....1..(3.....}.
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):7828992
Entropy (8bit):7.921525893053503
Encrypted:false
SSDEEP:
MD5:39810876629E0F99D86C93E99B6613ED
SHA1:B30E2BE50A07985ED869A7CBF3897BFC728E2326
SHA-256:35217C89202AC2839E31FFC143C8D7C99E6F36119270C6A15BBEA1EB1DB628F1
SHA-512:E60BA06321EB0B57B62655A8D830384093F72BD7C48F34FB37AA0888149914D5A9DFDBC64F4056F440C8BDF73B71204ADB5AA0875064786ECF52D0D2FF1A308E
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c.........." ..0..lw..........w.. ....w...... ........................w...........`...................................w.O.....w.@.....................w.....h.w.............................................. ............... ..H............text....lw.. ...lw................. ..`.rsrc...@.....w......nw.............@..@.reloc........w......tw.............@..B.................w.....H.............................i...........................................{....*N..}.....r...p(G...*..{....*N..}.....r...p(G...*..{....*N..}.....r...p(G...*..{....*N..}.....r)..p(G...*..{....*N..}.....r;..p(G...*..{....*N..}.....rQ..p(G...*..{....*N..}.....rg..p(G...*..{....*N..}.....r{..p(G...*..{....*N..}.....r...p(G...*..{....*N..}.....r...p(G...*..{....*N..}.....r...p(G...*..{....*N..}.....r...p(G...*..{....*N..}.....r...p(G...*..{....*N..}.....r...p(G...*..{....*N..}....
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):20480
Entropy (8bit):5.468345842624653
Encrypted:false
SSDEEP:
MD5:9F28D4C8972BF2540A65D58208E52971
SHA1:56F4AC3E1EF0E5A41F2C4775B8EB78F9DFA490CF
SHA-256:EA2BDBFA6DAFFC65218F8D95CDE32417D9BE00DCCF6395B8E3A43D7AB6244FEB
SHA-512:9702E2F574A01F7381408DA927ACC35792C214D861AEFE1ABD791F9281C875447146C5A353B1B93F122A0BA8C104AF9235812724A188E10C5902C713F491B330
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c.........." ..0..H..........2f... ........... ....................................`..................................e..O....................................d............................................... ............... ..H............text...8F... ...H.................. ..`.rsrc................J..............@..@.reloc...............N..............@..B.................f......H........,..X)...........U...............................................0.."........(.....(.......s....%.}.....(....*...0..+.........(....}.......}.......}......|......(...+*6..s....(....*....0..$........{....,.*..}....r...p.s.......(....*.0............YE............3...K...+m..t....}....*..t....}.....{...........s....o....*.t...........s....o....*..t....}.....{...........s....o....*..}....*2.{....o....**.(.......*2.{....o....*..{....*R.rS..p.|.....(...+&*..{....*R.rm..p.|..
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):10752
Entropy (8bit):5.118865749168938
Encrypted:false
SSDEEP:
MD5:03792132E15585CFBE8F7CA57B53DD4B
SHA1:8F1753178FB2B58B38D8D5D2E523D63D4E0FD700
SHA-256:EF97DAAC70F8C3A4E436F21277DAA92D7519692554ED85BBB2BDCAB141D44B23
SHA-512:0294B7FF4934829552E3A00FF2CC99A2FC83C80C565B4D736E003E88071C35748FEA3DB2B7F57F5FF1FAF2A0090DE57BC4149FB433DB3490FD48250F70173969
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....}^.........." ..0.."..........JA... ...`....... ....................................`..................................@..O....`...............................?............................................... ............... ..H............text...P!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............(..............@..B................,A......H........'................................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*:.(......(....*.~......'...s.........s.........~......&...s....(....&*...0..........(....r...po....~..........(....~....~....%-.&~......(...s....%.....(...+(...+...+......~......o....&..X....i2....,..(..... `...(....+...........Yp........-!~....%-.&~......)...s....%.............(....*....0..........~..........(....~....o.....+?..(
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):1805312
Entropy (8bit):6.645508870104047
Encrypted:false
SSDEEP:
MD5:403CD2799955C678726B5F04FA891B25
SHA1:189D3BD567349AC6DAF1B6E396985498DBD213EC
SHA-256:0A650CA8FFC9631908ED63F4D61357A45410055F3FB066BEFDF27514966D7B7B
SHA-512:FEE162BEFFE307A488D3150A5F0C532968C0D3AF8F2A31D3C45E37D7882EE4BC5BEB8647AB8AB3ED2AE7CD62B84CD83685FBB9391C5D7031DD9FD0BE418819A8
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...f..c.........."...0.............*.... ........@.. ....................................`.....................................O.................................................................................... ............... ..H............text...0.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......4....P...........-..............................................6.(.....(....*N..s....(.....(....*...0..+........u......,..o.....(....,.*.o....o....(....&*..0..$........{....,.*..}....r...p.s.......(....*.0............YE................7...D...Q...i...8......t....}....*..t....}....*.t...........s ...o!...*..t....}....*..t....}....*.t...........s ...o!...*..t....}.....{...........s"...o#...*..}....*....0..Q.......s.........s$........~%........~&........~'........~(....
Process:C:\Windows\System32\msiexec.exe
File Type:XML 1.0 document, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):4323
Entropy (8bit):4.889095952074509
Encrypted:false
SSDEEP:
MD5:A24309E3C13323A974BFAA26C469837E
SHA1:886BACB4356E760F77E27CD20A5C8F0ADB89313A
SHA-256:D77F7B110FA245048A532128719906E2AAB15AD263F84EFAF119315425C8AEB2
SHA-512:11117E58780FFF0E3413C975608D33424E84BE25CC4113E4D233A3B5A173CBAEE0807E8AFCB95EE444CE03FA03F05B26DC79A7EE6699723101716846E7BB72EA
Malicious:false
Reputation:unknown
Preview:<?xml version="1.0"?>..<configuration>.. <configSections>.. <sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089">.. <section name="B2.ControlCenter.Properties.B2CoreSettings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false"/>.. <section name="B2.ControlCenter.UI.Properties.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false"/>.. <section name="B2.Logger.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false"/>.. </sectionGroup>.. <sec
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):50688
Entropy (8bit):5.618221648482328
Encrypted:false
SSDEEP:
MD5:CEC77EAA8F4CE3F6D12C1605D5FDA92A
SHA1:BE2BC90118DD0678AFE1AA88FB0231886ADE577E
SHA-256:5850377000BD81BBAF9EB1156F59909D9177478103589480D62458F73344DFDB
SHA-512:EADA4EF11743701CA42E7A9169D89BF94E0B10BE036811DFC0D48B54A0B71C30E00F14CBEEFAFF77821EC2B0CBC7B318C04A39F1734F499A883D73A86A29829D
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c.........." ..0.................. ........... ....................... ............`.................................|...O...................................D................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......(n...n............................................................{....*"..}....*..{....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..( ...*6..(....o#...*.0..F........(....,3.r...p(.....(....r...po....,...%.(.....*..%.(.....*..%.(.....*...0..7........{....,)s..........(.....{......ou......,..(.......&..*..........'..........33.......0..Z........{....,(s..........(.....{....ox.....2.,..(.....s....%.o....r...p(....&r...p...&..r.
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):48640
Entropy (8bit):5.326288775753147
Encrypted:false
SSDEEP:
MD5:3801185F7782FCE204B1ADF1FDED19E6
SHA1:A861AB0981157371BFF55EE722FA8A629EBA66D4
SHA-256:853B36602EBD919602C0E1B777FF937253B112933F06BDB7201DC6039F756FEC
SHA-512:17096D3F217DDFF5702F8DAE433644DBBA7173268246EE62D8966BF992CE565228C7F9FF3460AD83F08617E71883CDF5C3C0A66BB865369C84EB368EB14A3872
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...._{V...........!................>.... ........... ....................... ............@.....................................S.................................................................................... ............... ..H............text...D.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B................ .......H.......xe..8n..................P .........................................Z.D..A....7..^9....?f9@.8me...Rj-...FW..7...M.!...m[..o..b.Q.....Y..v.p..9 .kf...',..O.W...H..LM....7......b|..dX~2A.|.0............(0....+..*.0...........s......o.....+..*...0............($....+..*.0............{.....+..*.0............{.....+..*.0............{.....+..*&...}....*...0............{.....+..*&...}....*...0............{.....+..*.0............{.....+..*&...}....*...0............{.....
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):431616
Entropy (8bit):5.945800143268636
Encrypted:false
SSDEEP:
MD5:C2A77547F66F8AFF1A0B436F4EC0846B
SHA1:7741AC9C5AF73E4D135B9FAE06031784E4ECE495
SHA-256:E06795B4337771504BFA6A3B5D7CB8307BBA00C7BAA2B061D4CD224207E0D3BA
SHA-512:69BA135BEFFEEB159064F84C408EF10A89BE4EB1EDA97BE23E95D7EDBC9C1BDACDD98A0F7E9AD80A8495BD7F7C165E1E2B054E757D0BF9B5B67147827494E71B
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....V.O...........!..................... ........@.. ..............................5.....@.................................H...S.......h...........................|................................................ ............... ..H............text........ ...................... ..`.rsrc...h...........................@..@.reloc..............................@..B........................H....................... .......P ......................................A}..Q/./.9.....t`.o.....,.LL.G....dk..e0V./.....uD.....5.<I..b.~Rr...n.#(..J.8.t..q..."U.VZ....,...8.*.Gx.'x..!.]|..O^...p.*...0..3............(....-.r...p( ...........s!.............("...*"..(#...*.0..!........o$...s%.....o&.......,..o......*..................."..s(...*..()...*....0..q.......s*.....o+....+'.o,.............o$...o-...&.r...po-...&.o....-....,..o......o/....1..%o/...r...po0...Yo1....o
Process:C:\Windows\System32\msiexec.exe
File Type:XML 1.0 document, Unicode text, UTF-8 text, with very long lines (359), with CRLF line terminators
Category:dropped
Size (bytes):827880
Entropy (8bit):4.583654568650992
Encrypted:false
SSDEEP:
MD5:483982A341AB86A1C80DCDC6EE393527
SHA1:C6B8067B884B711982A855ECC6273C357CF61D42
SHA-256:78287083DFDA99C115F0B8200BF3E60CB9F6E9018E9851899282DB9A086BE692
SHA-512:8758D9F1A899D3CC493B5EFDC295FF5D2DD2A2D55084006FAE5A7EACFF77B76849282204EF97B58FF3200FB3469C2AABF008C18AFA86D6A5E6CB0C460881E4A5
Malicious:false
Reputation:unknown
Preview:<?xml version="1.0"?>..<doc>.. <assembly>.. <name>InTheHand.Net.Personal</name>.. </assembly>.. <members>.. <member name="M:InTheHand.Net.ExceptionExtension.ToStringNoStackTrace(System.Exception)">.. <summary>.. Get the normal first line of <c>Exception.ToString()</c>,.. that is without the stack trace lines... </summary>.. -.. <remarks>.. Get the normal first line of <c>Exception.ToString()</c>,.. that is including details of all inner exceptions,.. but without the stack trace lines... e.g. <c>System.IO.IOException: An established connection was aborted by the software in your host machine. ---> System.Net.Sockets.SocketException: An established connection was aborted by the software in your host machine.</c>.. </remarks>.. -.. <param name="this">The exception... </param>.. -.. <returns>A
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):253336
Entropy (8bit):5.819350851011498
Encrypted:false
SSDEEP:
MD5:2683263D74E7E449750E707F8C131579
SHA1:794E6B3A7B7536F2FE7A0B20413330D695454773
SHA-256:63387D0D62A091C81CBB22DADC0C1CA62E2E6C076486282C4705E28E616409D6
SHA-512:5F6948C3546F0E3F37AE26659EB45352941BC6258F42E03FAD5C8768A56D42324E18CE1C734F6702943ADBAF99E0BE7DD8F8726C6A6A1B8FB3CE93E0CBA151AF
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......[.........." ..0...... ........... ........... ..............................\.....@.................................\...O.......X...........................$................................................ ............... ..H............text........ ...................... ..`.rsrc...X...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 929 messages, Project-Id-Version: b2CC V3.75 'Po\304\215et vodi\304\215\305\257'
Category:dropped
Size (bytes):72820
Entropy (8bit):5.491193484808316
Encrypted:false
SSDEEP:
MD5:23AE4B383D936DE5212D0FC58546E7FB
SHA1:8F0282CAB1DFCA48B5F66720C0BB1F70A9BD6F87
SHA-256:0D677772CFB4C3945BB6043C76A1C1D24C0DBEA0CA37D93B1FF26DF787AD7796
SHA-512:DFFDD37EDB1DF28F8DDF665C9B143C4434D996EBC7BACE545B67ED23DD55594AA8983DEC9F7327B7127B5CCFB0BD1F6E99B3CAA1BC8A44BC3FE65C224A273710
Malicious:false
Reputation:unknown
Preview:................$.......,:.......M.......M.......M.......M.......M.......M..@....M......,N......5N......>N......IN......WN......nN.......N.......N.......N..E....N.......O.......O......(O......EO......KO......aO......lO......wO..T....O.......O.......O.......O.......O.......P.......P......%P......;P......HP......QP......fP......jP..H....P.......P.......P.......P.......P.......Q.......Q......3Q......HQ..+..._Q..0....Q.."....Q..(....Q..!....R......*R..).../R......YR..5...xR..7....R.......R.......R.......R.......S.......S......*S......BS......ZS......`S......jS......qS......xS......}S.......S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T......(T......4T......DT..(...QT......zT.......T.......T.......T.......T..!....T.......T.......T.......T.......T..5....U..8...>U..3...wU.......U.. ....U.......U..S....V..Q...ZV../....V..F....V..D...#W......hW......pW......yW.......W.......W.......W.......W.......W.......W.......W.......W.......W.......X.......X......*X......
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 929 messages, Project-Id-Version: b2CC V3.75 'Anz. Leiter'
Category:dropped
Size (bytes):73412
Entropy (8bit):5.289250077276902
Encrypted:false
SSDEEP:
MD5:AD8376056D84B1350F807EB7EEF13AAE
SHA1:EF9D7D364641211699D243BD6157CB7D66D957D1
SHA-256:F010283B3F0D68B1E92B3ED2B3134DAE7C3A20947D32EEBED091CBC8324ADB65
SHA-512:45A2E7A6217E19F7C8C8396B10BDB297A43E90E6FDC73F3E33F05B0020DFD4E4683DFBBB749558395008F18C6C080DCC649F2859DB7F6FBC7554C8664EDFFFDC
Malicious:false
Reputation:unknown
Preview:................$.......,:.......M.......M.......M.......M.......M.......M..@....M......,N......5N......>N......IN......WN......nN.......N.......N.......N..E....N.......O.......O......(O......EO......KO......aO......lO......wO..T....O.......O.......O.......O.......O.......P.......P......%P......;P......HP......QP......fP......jP..H....P.......P.......P.......P.......P.......Q.......Q......3Q......HQ..+..._Q..0....Q.."....Q..(....Q..!....R......*R..).../R......YR..5...xR..7....R.......R.......R.......R.......S.......S......*S......BS......ZS......`S......jS......qS......xS......}S.......S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T......(T......4T......DT..(...QT......zT.......T.......T.......T.......T..!....T.......T.......T.......T.......T..5....U..8...>U..3...wU.......U.. ....U.......U..S....V..Q...ZV../....V..F....V..D...#W......hW......pW......yW.......W.......W.......W.......W.......W.......W.......W.......W.......W.......X.......X......*X......
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 929 messages, Project-Id-Version: b2CC V3.75 '# de conductores'
Category:dropped
Size (bytes):75236
Entropy (8bit):5.25328031836322
Encrypted:false
SSDEEP:
MD5:12BC80448B392EB58B1E2143AA8E765E
SHA1:B6A645A88532C7388AAD3ED5143F77B8C6F6D6C5
SHA-256:FDF60B98921AC8720D642AFA316E239EC43F0D52AE66F4C7AADF27955829F78F
SHA-512:D487C9B1897D4C32465F25106BFE4FE4931485A6CA4E7244026088CA38602A504D216AEDCD70D3C63FD5928A24DCC4C4B228468DA02D7CA3EC2B472B60D11409
Malicious:false
Reputation:unknown
Preview:................$.......,:.......M.......M.......M.......M.......M.......M..@....M......,N......5N......>N......IN......WN......nN.......N.......N.......N..E....N.......O.......O......(O......EO......KO......aO......lO......wO..T....O.......O.......O.......O.......O.......P.......P......%P......;P......HP......QP......fP......jP..H....P.......P.......P.......P.......P.......Q.......Q......3Q......HQ..+..._Q..0....Q.."....Q..(....Q..!....R......*R..).../R......YR..5...xR..7....R.......R.......R.......R.......S.......S......*S......BS......ZS......`S......jS......qS......xS......}S.......S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T......(T......4T......DT..(...QT......zT.......T.......T.......T.......T..!....T.......T.......T.......T.......T..5....U..8...>U..3...wU.......U.. ....U.......U..S....V..Q...ZV../....V..F....V..D...#W......hW......pW......yW.......W.......W.......W.......W.......W.......W.......W.......W.......W.......X.......X......*X......
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 494 messages, Project-Id-Version: b2CC V3.73 'Nombre de conducteurs'
Category:dropped
Size (bytes):42991
Entropy (8bit):5.191532882506726
Encrypted:false
SSDEEP:
MD5:203CDC261E1E1D73DCC46140200C9812
SHA1:922AF37B79EAB76C833BFF4815CBAB245CB3BB4F
SHA-256:D1497CAB170AFDBD0431287561CBB206F7842DCCE22893C8803E4FB17B02A784
SHA-512:A23D2C61480D1383D17F42778FF9B8A47714307F739338A943A897FF6D9BF58368DA7A11E0921D544689DE4931ABB7D004A36EB63698444ED7B7A9657E707CC0
Malicious:false
Reputation:unknown
Preview:................................H)......I)......Y)......f)......u)......|).......).......)..E....).......).......)..T....*......Z*......j*......n*......y*.......*.......*.......*.......*.......*.......*.......*.......*..+....*..0...)+.."...Z+..(...}+..!....+..)....+.......+.......+.......,......!,......',.......,......<,......K,......d,......k,.......,.......,.......,..(....,.......,..!....,.......-.......-.......-..5...'-..8...]-..3....-..S....-..Q......./...p...F..................................../...... /......//......7/......B/......P/......`/......v/......./......./......./......./......./......./......./......./.......0.......0......30......J0......`0......t0.......0.......0.......0.......0.......0.......0.......0.......1......'1......:1......N1......f1......n1.......1.......1.......1.......1..>....1..I....1..)...?2..$...i2.......2..,....2.......2.......2.......3.......3.."...23......U3......i3......x3.......3.......3.......3.......3.......3..<....3.......4.......4......&4......
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 479 messages, Project-Id-Version: b2CC V3.73 'Numero di conduttori'
Category:dropped
Size (bytes):40056
Entropy (8bit):5.065045652376136
Encrypted:false
SSDEEP:
MD5:D48A56E222A818B6D78B1D3925C3C65F
SHA1:DEF43C3767A781DAFAFCCAC19F68309DE4456374
SHA-256:936E1A2E629BC16C87BB2D62AB26F7B4FF8E7BACD27B90D23BFE495E7E7ED4EF
SHA-512:65A3D99DCF4E0135077763775BF1A70997FC498FF4210C82D9E059B5B6FA7356CE94CA7D912FE72B06B30F7FBB5CE164DB76C34CE9E663AF8EBFB3C24E899CF0
Malicious:false
Reputation:unknown
Preview:.................................(.......(......!(.......(......=(......D(......M(......X(..E...q(.......(.......(..T....(......')......7)......;)......F)......P)......])......f)......j)......y).......).......)..+....)..0....).."....*..(...**..)...S*......}*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......+.......+.......+..(...;+......d+..!...r+.......+.......+.......+..5....+..8....+..3...',..S...[,..Q....,../....-..F...1-......x-.......-.......-.......-.......-.......-.......-.......-.......-.......-......................4.......<.......J.......X.......f.......x......................................................................../......./......./......;/......N/......a/......v/......}/......./......./......./......./......./.......0.......0...... 0......)0......40..>...A0..I....0..)....0..$....0.......1..,...H1......u1......~1.......1.."....1.......1.......1.......1.......1.......2.......2......"2......62..<...B2.......2.......2.......2.......2......
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 363 messages, Project-Id-Version: b2CC V3.73 '# Av Dirigenter'
Category:dropped
Size (bytes):28084
Entropy (8bit):5.146676570886068
Encrypted:false
SSDEEP:
MD5:BBEAEBA6531D9A823ECDBAF0A88FDC3C
SHA1:B480512FDBAC4BED89CEF7876A9359619344A63E
SHA-256:CB54B876CF894292A2E680B62799ECE252728F44E0757021FF01DD327447140C
SHA-512:6C02E7F5F266F189FDD9B4B8AFC6A308997D4B591C598A619C055906FA9C42D6FA787D592BBD846840D624352EF0D153954FC9246C74C22C82E3DF6ABFCACDA2
Malicious:false
Reputation:unknown
Preview:........k.......t...............h.......i.......y...................................T...................#.......'.......2.......<.......I.......M.......\.......m.......{...................+.......0.......".... ..(...1 ..)...Z ....... ....... ....... ....... ....... ....... ....... ..(.... ..!.... .......!..5....!..8...S!..3....!..S....!..Q...."../...f"..F....".......".......".......".......#.......#......%#......-#......8#......F#......V#......l#.......#.......#.......#.......#.......#.......#.......#.......#.......$.......$......,$......9$......L$......_$......t$......{$.......$.......$.......$.......$.......$.......$.......$.......%..>....%..)...R%..$...|%.......%.......%.."....%.......%.......&.......&.......&......0&......;&......O&..<...[&.......&.......&.......&.......&.......&.......&.......&.......&.......&.......'.......'......9'......?'......Y'......o'......}'.......'.. ....'.......'.......'.......'.......'.......'..[....(..v....(..E...u)..L....)..N....*..L...W*.......*......
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 929 messages, Project-Id-Version: b2CC V3.75 '# Geleiders'
Category:dropped
Size (bytes):72861
Entropy (8bit):5.219016270843891
Encrypted:false
SSDEEP:
MD5:71A1A636DCB2483B2FCA57945E7BAE77
SHA1:5CA74168FA73D1B786306CCEBFEB57E6C53BF166
SHA-256:14ED90DCBF7A99319D81207F510D4CC945B1BC58816B3B6F859BFF00EEAF74B1
SHA-512:CCFE6E4037DFFC6F7298181CCC206DC77CC80BA06ECDA49D8ABB25A83CA9ED18219245244CAA380354ECAE8E77FFE60481CB2FF817EEADD700EEB1150DE585CF
Malicious:false
Reputation:unknown
Preview:................$.......,:.......M.......M.......M.......M.......M.......M..@....M......,N......5N......>N......IN......WN......nN.......N.......N.......N..E....N.......O.......O......(O......EO......KO......aO......lO......wO..T....O.......O.......O.......O.......O.......P.......P......%P......;P......HP......QP......fP......jP..H....P.......P.......P.......P.......P.......Q.......Q......3Q......HQ..+..._Q..0....Q.."....Q..(....Q..!....R......*R..).../R......YR..5...xR..7....R.......R.......R.......R.......S.......S......*S......BS......ZS......`S......jS......qS......xS......}S.......S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T......(T......4T......DT..(...QT......zT.......T.......T.......T.......T..!....T.......T.......T.......T.......T..5....U..8...>U..3...wU.......U.. ....U.......U..S....V..Q...ZV../....V..F....V..D...#W......hW......pW......yW.......W.......W.......W.......W.......W.......W.......W.......W.......W.......X.......X......*X......
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 929 messages, Project-Id-Version: b2CC V3.75 '# \305\274y\305\202'
Category:dropped
Size (bytes):72631
Entropy (8bit):5.463615976360198
Encrypted:false
SSDEEP:
MD5:7747E8B7B21197D32965C91AC5034A1E
SHA1:1E1DE757EF02701169B3C9062B5F33C53C5BA1BD
SHA-256:4865133B6AEAD82C46E1A5D4CC540EA952F8DF1A1370B7E9001E018D200880B8
SHA-512:C07258EB1461D72424DF2367B09A2D66690B1860E606279D966068EF774C894F27370154290BA7C66BD2862AFC101D8441C5C584E14106307C172CE430EFC3AD
Malicious:false
Reputation:unknown
Preview:................$.......,:.......M.......M.......M.......M.......M.......M..@....M......,N......5N......>N......IN......WN......nN.......N.......N.......N..E....N.......O.......O......(O......EO......KO......aO......lO......wO..T....O.......O.......O.......O.......O.......P.......P......%P......;P......HP......QP......fP......jP..H....P.......P.......P.......P.......P.......Q.......Q......3Q......HQ..+..._Q..0....Q.."....Q..(....Q..!....R......*R..).../R......YR..5...xR..7....R.......R.......R.......R.......S.......S......*S......BS......ZS......`S......jS......qS......xS......}S.......S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T......(T......4T......DT..(...QT......zT.......T.......T.......T.......T..!....T.......T.......T.......T.......T..5....U..8...>U..3...wU.......U.. ....U.......U..S....V..Q...ZV../....V..F....V..D...#W......hW......pW......yW.......W.......W.......W.......W.......W.......W.......W.......W.......W.......X.......X......*X......
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 498 messages, Project-Id-Version: b2CC V3.73 '\320\237\321\200\320\276\320\262\320\276\320\264\320\275\320\270\320\272\320\276\320\262'
Category:dropped
Size (bytes):51920
Entropy (8bit):5.4138574621393145
Encrypted:false
SSDEEP:
MD5:F795DBA840B4E51ADBD5139F22A0DDB1
SHA1:050FC618837E86B6B09D94A166079F99698CD013
SHA-256:25367579FEEBD3FA1153586A63498EAAFAC9496D98CABF381A6E009DCDD7ED6E
SHA-512:8F7DDCEE795B655B86B0763E1AD3EA6507C08553F6CCB9F8CD443B781F46AFF659C361065A40801223574DC592DB95F93A63F833E32C09E6E12AC34C605DE51B
Malicious:false
Reputation:unknown
Preview:........................<........).......).......).......).......).......).......).......*..E...!*......g*......m*......x*.......*..T....*.......*.......*.......*.......+.......+.......+......'+......++......:+......K+......Y+......k+......z+.......+..+....+..0....+.."....,..(...#,......L,..)...Q,......{,.......,.......,.......,.......,.......,.......,.......,.......,.......,.......,.......,.......-..(....-..!...<-......^-......d-......m-..5....-..8....-..3....-..S...%...Q...y.../.......F.......D...B/......./......./......./......./......./......./......./......./......./......./.......0.......0......'0......=0......U0......j0......r0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......1.......1......)1......?1......S1......X1......p1.......1.......1.......1.......1.......1.......1.......1.......1.......2.......2......42......T2......g2......{2.......2.......2.......2.......2.......2.......2.......2..>....2..I...03..)...z3..$....3.......3..,....3......%4......
Process:C:\Windows\System32\msiexec.exe
File Type:GNU message catalog (little endian), revision 0.0, 377 messages, Project-Id-Version: b2CC V3.73 '# \345\260\216\351\253\224\344\270\255'
Category:dropped
Size (bytes):27975
Entropy (8bit):5.879421543043671
Encrypted:false
SSDEEP:
MD5:C125F81976CF161419D0CF078A5B2965
SHA1:878E3F28E854EFC0AAFB5F2346ABC3C5D61CFAE1
SHA-256:24657EB4C8EEDE611E7393AF472F4D74E091CD8B262595B86972AEA05AE2E5E9
SHA-512:F0189E1F50B9FBD909E25CA94B570AFBAB53EFB741C0234BA98119A950757EB159F440F63F8928274C011F0611C7A745D656C646AE97869E1D99820E9ACDE0C3
Malicious:false
Reputation:unknown
Preview:........y...........................................................................................................T.... ......d ......t ......x ....... ....... ....... ....... ....... ....... ....... ....... ....... .......!..+....!..0...B!.."...s!..(....!.......!..)....!.......!.......!.......!......."......."......."......("....../"......;"......L"......U"..(...b"..!...."......."..5...."..8...."..3..."#..S...V#..Q....#../....#..F...,$..D...s$.......$.......$.......$.......$.......$.......%.......%.......%.......%......(%......:%......H%......X%......n%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......&......$&......:&......N&......S&......l&......y&.......&.......&.......&.......&.......&.......&.......'.......'......!'......2'......H'......Q'......\'..>...i'..)....'..$....'.......'.......(.......(.."...6(......Y(......m(......|(.......(.......(.......(.......(..<....(.......(.......)......*)......:)......E)......N)......c)......x).......)......
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):253952
Entropy (8bit):5.683351885696719
Encrypted:false
SSDEEP:
MD5:791DFA60E69134C8DAEFB72E98BB662D
SHA1:57AE5C3C91077762DE234574068BBD4B817EA728
SHA-256:8DDF429E0A57DF4B5A04EE1DB3F4AE1CCF70607A95187607D90CC8FAF978F96A
SHA-512:10D3694E5B787C72F473082B1D027D71A526BDC904DB4E6A3C6EF3B7003D80552F352DD99B7F409DB77FB315F1E1BF37955FBF1A79F36683CD7891A573D382D8
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....(VO...........!......... ......n.... ........... ....................... ............@.....................................O.................................................................................... ............... ..H............text...t.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):139264
Entropy (8bit):5.406435623463496
Encrypted:false
SSDEEP:
MD5:1C9662B2BFDB9DC00E31B35F2C04C423
SHA1:0EF325AD81A24BB77DE127FE14B939C898AB3575
SHA-256:83D15E1DB581942FD18DA30E1C9841977EC490957D7BEE0CC484EB4C8575B3DB
SHA-512:E9B008948D7F850D946E54CBFBF95C21F111F8755F42DED20B687633FB527E732394DB4914B20F847BFD05392A4F5CC5F83E5B5456511EA4A6452A50A498FD02
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....(VO...........!......... ........... ... ....... .......................`......./....@.....................................W.... ..p....................@....................................................... ............... ..H............text...$.... ...................... ..`.rsrc...p.... ......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):81920
Entropy (8bit):5.124202862914015
Encrypted:false
SSDEEP:
MD5:9F248BD709339B1AF7A6F902F7BDB43D
SHA1:6F27371C5E82BB957105EAD473BF03B92D6ADEF4
SHA-256:43046A4BE2BF9D876F937C117A3056BBD8341187E6054CFBD3D44632EEE5A6D3
SHA-512:5ECC262B9B762E2D942879DBAD74AC62B027FBDE373BB5857693DF3FDDCFEF865ED708AE51493F5386F53D0B17ACB3B1B68D7C4924E0463419D251523A6B0F70
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....(VO...........!......... .......*... ...@....... ....................................@..................................*..W....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@....... ..............@..@.reloc.......`.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):39936
Entropy (8bit):5.656233759415931
Encrypted:false
SSDEEP:
MD5:AA05CDF386D9A680FB9648C7E284169F
SHA1:206A9BEE772A448819822CC6C2492E4C7198BD96
SHA-256:6CDE4A1227C9ECD9AFD2E99317FF5A5536A183AB8C23973483C9BA0F4510E8C3
SHA-512:23C32104A178320DA4020FA8B1A419C83ECB1452FD98D73585A69BDB87A14072433A7FFFDA6DE0B8985481E3E8E24EF74F70543369CE846B0B8888D512D0758E
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...b..W.........." ..0.............b.... ........... ....................................@.....................................O................................................................................... ............... ..H............text...h.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B................D.......H........\..PU..................X.........................................{....*"..}....*..{....*"..}....*..{....*Z.-.r...ps....z..}....*2.(....(....*..(......(.....s....(.....s8....o7...(....*6..(....(....*..0............(......(......&..*................6..s....(....*:..s.....(....*:...s....(....*>...s.....(....*Z.-.r...ps....z..o~...*&...o....*V.(.......o.....(....*......o....*b.(.........o......(....*R..r...p.(.....o....*..(......r...p.(.....o.....(....*^..r...p.(........
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):127368
Entropy (8bit):6.1201657093755095
Encrypted:false
SSDEEP:
MD5:6902E6BCFEDA83D84586BB50746AC86F
SHA1:5E02DA136E54172B56A1D89976BDCD1E1CC7CD41
SHA-256:74A68A5797B50516C25396C97633A3C8E37542C4D83414D83E511B142B78359B
SHA-512:57408FD96FB3F98105361F33C1D6A2F185AF07D3E6D075B74775E120EC7BE8E850951BEB50D251C9925E65E08BAFD3157EC62BC35120D3D5AACAECEC7FE66F00
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...hS.\...........!..................... ........@.. ....................... ............@.....................................S.......(................?........................................................... ............... ..H............text........ ...................... ..`.rsrc...(...........................@..@.reloc..............................@..B........................H...........d$..................P .......................................N....B,~..9.t +.......b.vJ+....M..3....(....@+...n(.0..0YsH.ZXm<}.H......O.....au..`...4N...z~vv.....w..x.n.W....b=.0..-.......s6.......o7......o7......o7......o7.........*2~.....o8...*2~.....o9...*..0..x.......s:.......o;......o;......o;......o;........o;.......o;.......o;.......o;.......o;.......o;........o;........o;.........*2~.....o<...*2~.....o=...*...0..w.............,.......-.s?...z.{
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):184320
Entropy (8bit):5.593696105616633
Encrypted:false
SSDEEP:
MD5:4AC4B053B385C70B45F660845A5FFF0B
SHA1:552800FB15109F5BF4CEBC4B5F1370593A89457D
SHA-256:2E7B2211ED81CBF63823106B5C5FA7EC3A94B2468A0035AFCA526C409DB1F627
SHA-512:DE69E72E0586EB73E929BFDC06C9DE2AB2C0232013C1DA7719D480A1DE04951E3A763B52B74BDADA98D2E894714903536721659E8B22A234CA8CD65A8EFC07AD
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....0J...........!......... .......... ........... ....................................@.....................................K.................................................................................... ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):558080
Entropy (8bit):5.861798348492125
Encrypted:false
SSDEEP:
MD5:8EAF4F4363E87F924602CFD6B6B894AC
SHA1:63F04ABCC6CFD5E86E8D9DFBA5CF7E4CA287659F
SHA-256:B8CDF87B70E0CE565D5A2553088888B1A97792A5106B48A6986D5FF72DB08C64
SHA-512:FF27A501A73C29A12DF18F766D9610D2FC88019CB2E78B5A9B46B7DCFF038C7CE56C8DEBDC68B2EE412F172A17385275048CA77759205D6A9FC85DA42CEAE39E
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....(VO...........!.....z..........n.... ........@.. ...............................O....@................................. ...K.......p............................................................................ ............... ..H............text...ty... ...z.................. ..`.rsrc...p............|..............@..@.reloc..............................@..B................P.......H...............................P .......................................N..&.. .t....s..!A+O..$U.{..Bi.Jl:....3KV......_!w..Z........~.))Eo.**....*.dFF...H#>...Z.{...4.Gi...g..Y.E._..W\i.n.HLZ:.0.............+... ....Z......+...%.X.... ....2.+...%.X..... ....2.+...%.X.... ....2.+...%.X.... ...2..s.....-.... .Z......+...%.X..... 2..s...........&r...ps....z*.................:.(4.....(....*..0..........~+....X.[....~+....X.[......+ ......1....[...%q[....X.[.....X....i2.
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):94208
Entropy (8bit):5.111249731100566
Encrypted:false
SSDEEP:
MD5:525F203916ECE58376281666A1A62310
SHA1:52A95DCB9B3B5EB1A6C0F841A415286B57028402
SHA-256:6F4E718425ABFC6B89AACF9916E5374A634D2387BD4EBD18235C86CC51A8E633
SHA-512:93CC40EECBCD6875D876DBDF1B24B4474FD82AD61EA14A12E82E954096E17199CA6CC77E0E56D6A817918AFA35166FCB7083A8469BCFEDE7B1254632BB487FA8
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....(VO...........!.....@... .......Y... ...`....... ....................................@..................................X..K....`............................................................................... ............... ..H............text...$9... ...@.................. ..`.rsrc........`.......P..............@..@.reloc...............`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):53760
Entropy (8bit):5.522843724534118
Encrypted:false
SSDEEP:
MD5:ECBE6D085CF0502062645B2234E85B99
SHA1:F647F0C7437D2A04A63D98DEA9DFDF54AE52EF7C
SHA-256:FD179648DE9D29414A8BD65BF5B94BE039FC58DB6498086CED6637F06A84CF09
SHA-512:0E6761D354F76836D3D8F327E18C9BB0B4BB363E235010C9A39D070FA4256D46B2FAB8CC22D805A6C27AEAD50ADA931A51F71EE5484D089150EC2DF5684A7A43
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....AtT...........!..................... ........... .......................@............`.....................................S.......X.................... ....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...X...........................@..@.reloc....... ......................@..B........................H........t...q..........................................................b.(........}......}.....*....0............{.....+..*.0............(....(.....+..*....0............{..............:........{....r...p.{....oM...o................-...r...p}.....r...p}.....+v...o....}.....{....o....r...po.............-..o....r...p(................-...{....}....+...{.....{....(....o`...}.......{.....+..*...0..+..........}.....{....r...p.{....oM...o..............-*..{....o....r...pr...po......
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):27136
Entropy (8bit):5.343845897201569
Encrypted:false
SSDEEP:
MD5:A0396D30DCE349CF70AE0F3283D31C29
SHA1:FA088A171190FCB602A82D84C8B336201B7D22A5
SHA-256:B0ED2886C79BA864E419CC2E52A95A2590EAA333839BE983DBCFD520F44D5C4F
SHA-512:C1E6E355497C19D3D8C31FAD5E9B3B47491EFEC1CABE7737A448ACAB375C9782F8AF2F9A2D8DBD00905FBEDFE07A3756495F86F53521198E23315DB858543093
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...G@-T...........!.....b..........>.... ........... ....................................`....................................W.......X............................................................................ ............... ..H............text...Da... ...b.................. ..`.rsrc...X............d..............@..@.reloc...............h..............@..B................ .......H........A...>............................................................(........(.......(.......(...+(......*.0............{.....+..*&...}....*...0............{.....+..*&...}....*...0............{.....+..*&...}....*...0............{.....+..*&...}....*...0..............{.....+..*...0..-...........%...(..........}.............-..(.......*....................0............{.....+..*&...}....*...0..1...........%...(........(..............-..(.........+..*....................0..
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):26624
Entropy (8bit):5.451991203774728
Encrypted:false
SSDEEP:
MD5:F68F8DD663FDB57127C4412629863DBF
SHA1:78333DDE912AB3CE786FCD009F679F5F44E3636D
SHA-256:C72A5874B1C926CC3902E05A51B779F4481D1D7FBF8F45F8BF8FB8E5839748FF
SHA-512:A0F26FD3F8568500615892CBFF19218BEC4F33BF079B909BD8DA0ADA6B3E166E173E48C0F48E6A076901D6F87AB2862EDA54E74A1D3C207625E2ECF7091A8595
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......O...........!.....`...........~... ........@.. ....................................@..................................~..O.......h............................}............................................... ............... ..H............text....^... ...`.................. ..`.rsrc...h............b..............@..@.reloc...............f..............@..B.................~......H........>...?...........................................................0..?........./.....0.....0...s:........../.....0.....0...s:...........0.....0...s:...........0.....0...s:..........0.....0...s...........0.....0...s............/...../...s:.........../...../...s:........../...../...../...s:........../...../...s.........../...../...s.........../...../...sA........../...../...s1........s$........*..0...........{.....+..*"..}....*.0...........{.....+..*"..}....*j.(........(
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):900608
Entropy (8bit):6.2820842710715885
Encrypted:false
SSDEEP:
MD5:0395A828FAFE353A9ED4765A588C54BB
SHA1:16AF0F43DB47FEE0C9067E3B7A9F0B7654296C9D
SHA-256:363DBB20C106F261DEEF1435C4D52CCBED702EC7410F0DE5DAEB0585D118F584
SHA-512:E8B3938DB2CE181A00E52724ABA6AE775997B8CE290D866ACCDB37C7B0F569EF83C30934EF614A6F5D3B73891C40AF2F7281D81139798CF6B395A2BAA594AF25
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...N..Q...........!................^.... ........@.. ....................... ............@.....................................K...................................P................................................ ............... ..H............text...d.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B................@.......H.......x...............`.......P .......................................$..jI.5e.....c.>zk.1.f.C.v..7...z..R..P.9u..>..Y*w..AD2.gG.Hu.....F..w.:.............n...yt...x..eB....;8..\...9....^.....Z.0..........r...p.9...(+........(+... .... .... .... ....(,...s-.....s....(/........r...p.;...(+........(+...(0....;.....s....(1........~....o2........r3..p.9...(+........(+... .... .... .... ....(,...s-.....s....(/........rK..p.9...(+........(+...(3.....s....(/........rg..p.<...
Process:C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Number of Characters: 0, Last Saved By: InstallShield, Number of Words: 0, Title: b2 ControlCenter Setup, Comments: b2 ControlCenter, Keywords: Installer,MSI,Database, Subject: b2 ControlCenter, Author: b2 electronic GmbH, Security: 1, Number of Pages: 200, Name of Creating Application: InstallShield 2018 - Express Edition 24, Last Saved Time/Date: Tue Nov 29 15:24:49 2022, Create Time/Date: Tue Nov 29 15:24:49 2022, Last Printed: Tue Nov 29 15:24:49 2022, Revision Number: {B1B7EEAC-19DF-4A66-92D0-4A9FA0D4FD78}, Code page: 1252, Template: Intel;1033
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:E86BE29833329F8E0E45FB0B6DFD8FA4
SHA1:CBF042C7115FCCBFAC7FB506E93B20E1B1493837
SHA-256:B1DCE6AE36642FE651E9971C8981DE82B17A4F12C16E807FAB437E8AD05CBF78
SHA-512:E7DDB4BE0684837DF600520AB07A7F7087C7C5DE78A550FFBBE24CBB7789984821D8FF2D1DECC164221DDEB2D56393D72BD192EF2D552875264B841B8C909B38
Malicious:false
Reputation:unknown
Preview:......................>...................................8........6........................................................................................................................................................................................................................................................................... ... ...!...!..."..."...#...#...$...$...%...%...&...&...'...'...(...(...)...)...*...*...+...+...,...,...-...-.........../.../...0...0...1...1...2...2...3...3...4...4...5...5..........;........................................................................................................... .......2...!..."...#...$...%...&...'.......)...Q...+...,...-......./...0...1...(...3...4...5...6...7...A...M...:...<.......=.......?...@.......B...C...D...E...F...G...H...I...J...Z...L...N.......O...P.......R...f.......U...V...W...X...Y.......[...\...]...^..._...`...a...b...c...d...e...h...g...r...i...j...k...l...m...n...o...p...q...t...s.......u...v...w...x...y...z...
Process:C:\Windows\SysWOW64\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):105688
Entropy (8bit):6.241698308556307
Encrypted:false
SSDEEP:
MD5:D506C8289968A1E7D4F17CF496643A60
SHA1:BE147E04A45534557671DF0284D476270EEA4189
SHA-256:655733E66CCA593E524C2B2F60A9F056E21EA3384E2C52BE3217563CFE6E343B
SHA-512:B5BCB4E3BD2EB3D52AD9F705001B0BB8E2966DCA0D71216CAAFFD6FDCCD8311F7ADEEA7D751725C6A3459F0379C49EEB3602DC12089B5D0CC5023E52F9B5BFBC
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........I!;.(Oh.(Oh.(Oh..h.(Oh..h.(Oh..h.(Oh.P.h.(Oh.(Nh.(Oh._.h.(Oh^.h.(Oh^.h.(Oh^.h.(Oh.(.h.(Oh^.h.(OhRich.(Oh........PE..L....h.[...........!.................V..............................................".....@.........................`Z......,S..x...................................................................8E..@...............X............................text............................... ..`.rdata...j.......l..................@..@.data....-...`.......H..............@....rsrc................X..............@..@.reloc..v ......."...^..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\SysWOW64\msiexec.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):169168
Entropy (8bit):6.059174301041458
Encrypted:false
SSDEEP:
MD5:B4404FBE8E2DFF187B143C88DA903C82
SHA1:6C5117D6AC6A88401363C41403FFFB7F96A3319D
SHA-256:D64807070C6B57700ECAAEF8D0FDF6637F348DC2DC6AA49DB65ED578D054F906
SHA-512:44E6C18BF7B7F431AF17C44E8A1D6F1F89CABDF449B4F0937862A44583A237605AB3035937689409FBD063126A51B83E77BA334C01DDCF4CD5C17F33EC9E5C07
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......._`,"..Bq..Bq..Bq..q..Bq<.q..Bq..q..Bq..q/.Bq..qh.Bq.y.q..Bq.y.q..Bq..Cq..Bq..q..Bq..q..Bq..q..Bq...q..Bq..q..BqRich..Bq........PE..L...Gm.[...........!.....p...$.........................................................................................m............`..p............x.......p..........................................@............................................text....o.......p.................. ..`.rdata..M............t..............@..@.data....1... ......................@....rsrc...p....`.......$..............@..@.reloc...L...p...N...*..............@..B................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe
File Type:Unicode text, UTF-16, little-endian text, with very long lines (308), with CRLF line terminators
Category:dropped
Size (bytes):22480
Entropy (8bit):3.4851320007899904
Encrypted:false
SSDEEP:
MD5:A108F0030A2CDA00405281014F897241
SHA1:D112325FA45664272B08EF5E8FF8C85382EBB991
SHA-256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948
SHA-512:D83894B039316C38915A789920758664257680DCB549A9B740CF5361ADDBEE4D4A96A3FF2999B5D8ACFB1D9336DA055EC20012D29A9F83EE5459F103FBEEC298
Malicious:false
Reputation:unknown
Preview:..[.0.x.0.4.0.9.].....1.1.0.0.=.S.e.t.u.p. .I.n.i.t.i.a.l.i.z.a.t.i.o.n. .E.r.r.o.r.....1.1.0.1.=.%.s.....1.1.0.2.=.%.1. .S.e.t.u.p. .i.s. .p.r.e.p.a.r.i.n.g. .t.h.e. .%.2.,. .w.h.i.c.h. .w.i.l.l. .g.u.i.d.e. .y.o.u. .t.h.r.o.u.g.h. .t.h.e. .p.r.o.g.r.a.m. .s.e.t.u.p. .p.r.o.c.e.s.s... . .P.l.e.a.s.e. .w.a.i.t.......1.1.0.3.=.C.h.e.c.k.i.n.g. .O.p.e.r.a.t.i.n.g. .S.y.s.t.e.m. .V.e.r.s.i.o.n.....1.1.0.4.=.C.h.e.c.k.i.n.g. .W.i.n.d.o.w.s.(.R.). .I.n.s.t.a.l.l.e.r. .V.e.r.s.i.o.n.....1.1.0.5.=.C.o.n.f.i.g.u.r.i.n.g. .W.i.n.d.o.w.s. .I.n.s.t.a.l.l.e.r.....1.1.0.6.=.C.o.n.f.i.g.u.r.i.n.g. .%.s.....1.1.0.7.=.S.e.t.u.p. .h.a.s. .c.o.m.p.l.e.t.e.d. .c.o.n.f.i.g.u.r.i.n.g. .t.h.e. .W.i.n.d.o.w.s. .I.n.s.t.a.l.l.e.r. .o.n. .y.o.u.r. .s.y.s.t.e.m... .T.h.e. .s.y.s.t.e.m. .n.e.e.d.s. .t.o. .b.e. .r.e.s.t.a.r.t.e.d. .i.n. .o.r.d.e.r. .t.o. .c.o.n.t.i.n.u.e. .w.i.t.h. .t.h.e. .i.n.s.t.a.l.l.a.t.i.o.n... .P.l.e.a.s.e. .c.l.i.c.k. .R.e.s.t.a.r.t. .t.o. .r.e.b.o.o.t. .t.h.e. .s.y.s.t.e.m.......1.1.0.8.
Process:C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe
File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
Category:dropped
Size (bytes):2412
Entropy (8bit):5.217629515334262
Encrypted:false
SSDEEP:
MD5:6FD9DB583E6B8E28049FC1C1B6A4ACB0
SHA1:50ECE1A252D3EAA2E8B7264606221E04EC0B85BD
SHA-256:5CEF6C564E81946D9C7D162A8B3A7D8B7FBB33607E1A7506BD3B0576CA8267A5
SHA-512:D64AD81F8EABB2B4B498E49AF4A89F464E401C25A6D4C508105AD736A80E7C026C2E95B6A4E106453C45B4E3A2716C5B0F7B849B3A018B88AD6E3B016A21676D
Malicious:false
Reputation:unknown
Preview:.<?xml version="1.0" encoding="utf-8"?>..<SetupPrereq>.. <conditions>.. <condition Type="2" Comparison="2" Path="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full" FileName="Release" ReturnValue="378389"></condition>.. </conditions>.. <operatingsystemconditions>.. <operatingsystemcondition MajorVersion="6" MinorVersion="0" PlatformId="2" CSDVersion="" Bits="1" ProductType="2|3"></operatingsystemcondition>.. <operatingsystemcondition MajorVersion="6" MinorVersion="1" PlatformId="2" CSDVersion="" Bits="1"></operatingsystemcondition>.. <operatingsystemcondition MajorVersion="6" MinorVersion="0" PlatformId="2" CSDVersion="" Bits="4" ProductType="2|3"></operatingsystemcondition>.. <operatingsystemcondition MajorVersion="6" MinorVersion="1" PlatformId="2" CSDVersion="" Bits="4"></operatingsystemcondition>.. <operatingsystemcondition MajorVersion="6" MinorVersion="2" PlatformId="2" CSDVersion="" Bits="1"></operatingsystemcondition>.. <operatingsys
Process:C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe
File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):5480
Entropy (8bit):3.7169014032571415
Encrypted:false
SSDEEP:
MD5:13CEEDE0CD2AA1F3BCE759F93222E6A8
SHA1:D1ED9E8999189AB8E8EE5246978AD05E7A8227AB
SHA-256:1CB113A9EA8E33D90DA55E2FFA1CF8C97C82339145B2D4A724C3F86CC92C0FC3
SHA-512:F511C6B1579D3C4BB8355BABBD23EADD9714E4FB348910751BF197ADC92D5BF05D7698AEFC7BB734F8B0A4675AF75C0DC2BF5FA5B0FB017C256D99BC6B0AC711
Malicious:false
Reputation:unknown
Preview:..[.I.n.f.o.].....N.a.m.e.=.I.N.T.L.....V.e.r.s.i.o.n.=.1...0.0...0.0.0.....D.i.s.k.S.p.a.c.e.=.8.0.0.0...;.D.i.s.k.S.p.a.c.e. .r.e.q.u.i.r.e.m.e.n.t. .i.n. .K.B.........[.S.t.a.r.t.u.p.].....C.m.d.L.i.n.e.=.....S.u.p.p.r.e.s.s.W.r.o.n.g.O.S.=.Y.....S.c.r.i.p.t.D.r.i.v.e.n.=.0.....S.c.r.i.p.t.V.e.r.=.1...0...0...1.....D.o.t.N.e.t.O.p.t.i.o.n.a.l.I.n.s.t.a.l.l.I.f.S.i.l.e.n.t.=.N.....O.n.U.p.g.r.a.d.e.=.0.....P.r.o.d.u.c.t.=.b.2. .C.o.n.t.r.o.l.C.e.n.t.e.r.....P.a.c.k.a.g.e.N.a.m.e.=.b.2. .C.o.n.t.r.o.l.C.e.n.t.e.r...m.s.i.....E.n.a.b.l.e.L.a.n.g.D.l.g.=.Y.....L.o.g.R.e.s.u.l.t.s.=.N.....D.o.M.a.i.n.t.e.n.a.n.c.e.=.N.....P.r.o.d.u.c.t.C.o.d.e.=.{.D.7.F.4.6.7.7.5.-.4.6.B.0.-.4.E.8.9.-.8.0.6.9.-.6.5.C.C.2.F.A.6.0.0.4.6.}.....P.r.o.d.u.c.t.V.e.r.s.i.o.n.=.3...7.5...1.0.....U.p.g.r.a.d.e.C.o.d.e.=.{.2.C.5.B.8.C.C.5.-.1.8.A.F.-.4.0.8.4.-.9.0.4.0.-.1.8.7.E.4.C.1.8.1.5.C.E.}.....L.a.u.n.c.h.e.r.N.a.m.e.=.s.e.t.u.p...e.x.e.....W.a.i.t.I.n.s.t.a.l.l.a.t.i.o.n.=.Y.....P.a.c.k.a.g.e.C.o.d.e.=.{.B.
Process:C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe
File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):1396
Entropy (8bit):3.693027505902493
Encrypted:false
SSDEEP:
MD5:F1CDCB07B41DC0647E53B28935064BC3
SHA1:C506C9533AAD361520001247F430919C6C55F295
SHA-256:9B1AEFA1C732993FB32F92CFA0BCC4EBABA6BAA9F9EEC7BC926168DDA72B95A7
SHA-512:175C5A79A10D399277A30E4D1DA47F1CDD075405A63BAC5769062B74FD386B02183B8471B32B0558A9EB107C48DACFF88DD4A620A1AD569910DB5948DCBFB08B
Malicious:false
Reputation:unknown
Preview:..[.F.i.l.e.s.].....0.x.0.4.0.9...i.n.i.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.{.1.2.B.E.B.B.F.B.-.A.3.7.1.-.4.6.B.3.-.A.0.D.0.-.5.0.A.2.0.0.8.B.5.0.C.2.}.\.0.x.0.4.0.9...i.n.i.....b.2. .C.o.n.t.r.o.l.C.e.n.t.e.r. .S.e.t.u.p. .V.3...7.5...e.x.e.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.{.1.2.B.E.B.B.F.B.-.A.3.7.1.-.4.6.B.3.-.A.0.D.0.-.5.0.A.2.0.0.8.B.5.0.C.2.}.\.b.2. .C.o.n.t.r.o.l.C.e.n.t.e.r. .S.e.t.u.p. .V.3...7.5...e.x.e.....b.2. .C.o.n.t.r.o.l.C.e.n.t.e.r...m.s.i.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.{.1.2.B.E.B.B.F.B.-.A.3.7.1.-.4.6.B.3.-.A.0.D.0.-.5.0.A.2.0.0.8.B.5.0.C.2.}.\.b.2. .C.o.n.t.r.o.l.C.e.n.t.e.r...m.s.i.....I.S.S.e.t.u.p...d.l.l.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.{.1.2.B.E.B.B.F.B.-.A.3.7.1.-.4.6.B.3.-.A.0.D.0.-.5.0.A.2.0.0.8.B.5.0.C.2.}.\.I.S.S.e.t.u.p...d.l.l.....M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k. .4...5. .W.e.b. ...p.r.q.=.C.:.\.U.s.e.
Process:C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):16740243
Entropy (8bit):7.964162789533916
Encrypted:false
SSDEEP:
MD5:F02023E1E165FB92ADAAB5BF1EF98ED9
SHA1:9DE491DA46B50716D1B8164221C9B84A111FDFC2
SHA-256:2A92AC98AE89F214CD10B1CA5EB26316BB588F73D5E0A2642C1768712FFB0AAD
SHA-512:4F0CC68D4065BF3FC0808734221894DACDC7689B27D8D8F316EB06B75064C0B37F9DB8D4A3852375D7ABF14966ADCFB5B13AEE7591F5EBC4D9BCF9AF0418DCDF
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......j.5...[...[...[..H..%.[..H../.[..I..7.[..I....[....-.[..I..l.[....9.[...Z..[..H..n.[..H../.[..../.[..H../.[.Rich..[.........................PE..L......[.................H...V......Zv.......`....@..........................P............@.................................(#..................................t....i..8..............................@............`......|........................text....G.......H.................. ..`.rdata..8....`.......L..............@..@.data........P...(...0..............@....rsrc................X..............@..@.reloc..f{.......|...&..............@..B........................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\b2 ControlCenter Setup V3.75.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):26
Entropy (8bit):3.95006375643621
Encrypted:false
SSDEEP:
MD5:187F488E27DB4AF347237FE461A079AD
SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
Malicious:true
Reputation:unknown
Preview:[ZoneTransfer]....ZoneId=0
Process:C:\Users\user\AppData\Local\Temp\{12BEBBFB-A371-46B3-A0D0-50A2008B50C2}\b2 ControlCenter Setup V3.75.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Number of Characters: 0, Last Saved By: InstallShield, Number of Words: 0, Title: b2 ControlCenter Setup, Comments: b2 ControlCenter, Keywords: Installer,MSI,Database, Subject: b2 ControlCenter, Author: b2 electronic GmbH, Security: 1, Number of Pages: 200, Name of Creating Application: InstallShield 2018 - Express Edition 24, Last Saved Time/Date: Tue Nov 29 15:24:49 2022, Create Time/Date: Tue Nov 29 15:24:49 2022, Last Printed: Tue Nov 29 15:24:49 2022, Revision Number: {B1B7EEAC-19DF-4A66-92D0-4A9FA0D4FD78}, Code page: 1252, Template: Intel;1033
Category:dropped
Size (bytes):16909824
Entropy (8bit):7.896342327863149
Encrypted:false
SSDEEP:
MD5:E86BE29833329F8E0E45FB0B6DFD8FA4
SHA1:CBF042C7115FCCBFAC7FB506E93B20E1B1493837
SHA-256:B1DCE6AE36642FE651E9971C8981DE82B17A4F12C16E807FAB437E8AD05CBF78
SHA-512:E7DDB4BE0684837DF600520AB07A7F7087C7C5DE78A550FFBBE24CBB7789984821D8FF2D1DECC164221DDEB2D56393D72BD192EF2D552875264B841B8C909B38
Malicious:false
Reputation:unknown
Preview:......................>...................................8........6........................................................................................................................................................................................................................................................................... ... ...!...!..."..."...#...#...$...$...%...%...&...&...'...'...(...(...)...)...*...*...+...+...,...,...-...-.........../.../...0...0...1...1...2...2...3...3...4...4...5...5..........;........................................................................................................... .......2...!..."...#...$...%...&...'.......)...Q...+...,...-......./...0...1...(...3...4...5...6...7...A...M...:...<.......=.......?...@.......B...C...D...E...F...G...H...I...J...Z...L...N.......O...P.......R...f.......U...V...W...X...Y.......[...\...]...^..._...`...a...b...c...d...e...h...g...r...i...j...k...l...m...n...o...p...q...t...s.......u...v...w...x...y...z...
Process:C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe
File Type:XML 1.0 document, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):352
Entropy (8bit):4.581001753851005
Encrypted:false
SSDEEP:
MD5:987E0A416689A7A5C03ED05101A8DDAC
SHA1:79F6FE21390A11E1F5E5257C6B9BDB947F1AA1BE
SHA-256:AC0D84D52B5E6520F94A00DF44730BDFA8CAECD69B182EE0745F9D6F01BD72AC
SHA-512:F45FB2F682F09C297CB197478E911F6472B379B78A8C6884C0D6A31AB18D73F261F222F051B515CEC7041B0031C64EA57BCDA3DAB15BF97EE472DFA2B81B0580
Malicious:false
Reputation:unknown
Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <userSettings>.. <B2.ControlCenter.UI.Properties.Settings>.. <setting name="IsFirstApplicationRun" serializeAs="String">.. <value>False</value>.. </setting>.. </B2.ControlCenter.UI.Properties.Settings>.. </userSettings>..</configuration>
Process:C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe
File Type:XML 1.0 document, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):596
Entropy (8bit):4.499216361743422
Encrypted:false
SSDEEP:
MD5:17869DA4F53EE69264607B650D8FA074
SHA1:9A3726040D8DAE0DC67D95147F7518E2227E5D75
SHA-256:EDA0AD2C10AD68991FC187E26CC08FB4084D5FD6BB307999C62F82F9D017E39D
SHA-512:DDDE6E5897EAB5EA8CA7BD6DAF27FC8514AE4FF8C98A45549D2BF91A833ADD385786B425099473F50ABAE658082EB530319F2F38B6B2584A15D8B472AE5F29FE
Malicious:false
Reputation:unknown
Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <userSettings>.. <B2.ControlCenter.Properties.B2CoreSettings>.. <setting name="IsFirstApplicationRun" serializeAs="String">.. <value>False</value>.. </setting>.. </B2.ControlCenter.Properties.B2CoreSettings>.. <B2.ControlCenter.UI.Properties.Settings>.. <setting name="IsFirstApplicationRun" serializeAs="String">.. <value>False</value>.. </setting>.. </B2.ControlCenter.UI.Properties.Settings>.. </userSettings>..</configuration>
Process:C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe
File Type:XML 1.0 document, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:987E0A416689A7A5C03ED05101A8DDAC
SHA1:79F6FE21390A11E1F5E5257C6B9BDB947F1AA1BE
SHA-256:AC0D84D52B5E6520F94A00DF44730BDFA8CAECD69B182EE0745F9D6F01BD72AC
SHA-512:F45FB2F682F09C297CB197478E911F6472B379B78A8C6884C0D6A31AB18D73F261F222F051B515CEC7041B0031C64EA57BCDA3DAB15BF97EE472DFA2B81B0580
Malicious:false
Reputation:unknown
Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <userSettings>.. <B2.ControlCenter.UI.Properties.Settings>.. <setting name="IsFirstApplicationRun" serializeAs="String">.. <value>False</value>.. </setting>.. </B2.ControlCenter.UI.Properties.Settings>.. </userSettings>..</configuration>
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):409600
Entropy (8bit):5.76507051578974
Encrypted:false
SSDEEP:
MD5:361980F7B13653FE956B9E0298FAE998
SHA1:55D3364D319F2A2D41DE4964F4F209E97B035AAA
SHA-256:EDA18B0D35E8A8C212B92018F1EFE295FBDE6349E7170FD7E8546269A01B0942
SHA-512:8573D6FD1E594D34323F8C3F82FA0BB264D16FFE1A5F48A4E1B36E75377FF5B89DC23FF079E7A664C4D8DCA2C433BEAAE13AC77500272B4D8C5C8971141DC823
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............C...C...C...C...CD..C...C...C...C=..C...C...C...C...C...CRich...C........................PE..L.....[.................@...................P....@..........................@..............................................4T..(.......x............................................................................P...............................text....5.......@.................. ..`.rdata.......P.......P..............@..@.data....)...`...0...`..............@....rsrc...x...........................@..@................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):409600
Entropy (8bit):5.76507414779012
Encrypted:false
SSDEEP:
MD5:16DA970713D4CAE40BD06976A908B12C
SHA1:EA35115A8D77B51F86AF764AA69BDE5D74378854
SHA-256:89403E1641E1D87B125577D927CB681781C2817D05C155486696B9D984EE9D6D
SHA-512:DE767AF94B848DF47A89CAA73F8052291A1832EA5ED3F690CFC1DC6717F10B176B083CB52483F35F62A8081BC60771360A22182AAEF1B865B776E236962A2236
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............C...C...C...C...CD..C...C...C...C=..C...C...C...C...C...CRich...C........................PE..L.....[.................@...................P....@..........................@..............................................4T..(.......x............................................................................P...............................text....5.......@.................. ..`.rdata.......P.......P..............@..@.data....)...`...0...`..............@....rsrc...x...........................@..@................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Icon number=0, Archive, ctime=Tue Nov 29 18:04:24 2022, mtime=Mon Oct 14 06:36:49 2024, atime=Tue Nov 29 18:04:24 2022, length=1805312, window=hide
Category:dropped
Size (bytes):2376
Entropy (8bit):3.9809373571483406
Encrypted:false
SSDEEP:
MD5:14947310CD90DCE4DA1B0135925BF57C
SHA1:B54F44CFA9D8A086DE7576582B59DBCF53A6F790
SHA-256:2B59B04561966A2089B5A0B6408BEBFF51FD7997B9AF0BA90E20E0515B278FDF
SHA-512:D23BB571C496D9C2AE5FE5C980CA43F5FC985ACB26C9339F343164D80FD0CC2F20A32CA39C44EE4B6EAD35492E88A5CC8403D85893DC0A0429DC60A983EE45F5
Malicious:false
Reputation:unknown
Preview:L..................F.@.. ....,.e%............,.e%................................P.O. .:i.....+00.../C:\.....................1.....NY.<..PROGRA~2.........O.INY.<....................V.......a.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....n.1.....NY.<..B2ELEC~1..V......NY.<NY.<...........................La.b.2. .e.l.e.c.t.r.o.n.i.c. .G.m.b.H.....j.1.....NY.<..B2CONT~1..R......NY.<NY.<..........................&...B.2. .C.o.n.t.r.o.l.C.e.n.t.e.r.....x.2.....}U.. .CONTRO~1.EXE..\......}U..NY.<....F.........................C.o.n.t.r.o.l.C.e.n.t.e.r...A.p.p...e.x.e.......................-.......~....................C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe..k.....\.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.b.2. .e.l.e.c.t.r.o.n.i.c. .G.m.b.H.\.B.2. .C.o.n.t.r.o.l.C.e.n.t.e.r.\.C.o.n.t.r.o.l.C.e.n.t.e.r...A.p.p...e.x.e...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Icon number=0, Archive, ctime=Tue Nov 29 18:04:24 2022, mtime=Mon Oct 14 06:36:50 2024, atime=Tue Nov 29 18:04:24 2022, length=1805312, window=hide
Category:dropped
Size (bytes):2334
Entropy (8bit):3.98874902810683
Encrypted:false
SSDEEP:
MD5:4553E58D4F01306BC19D05C83221B537
SHA1:85CED948662DE61F8094DCD1E9E77772F9B39426
SHA-256:46B8081667405F16D5B25AB0FDF35C48253F03140E9394EA69C3ACBDC7546F14
SHA-512:D882E138330E190F037987DE8C6D0688F8367202E6A99CDBF6330C922A428915A0E644025DA3B2F43E35803BCD981CB7DA02F3391BAB2F6D3FAF63B034444669
Malicious:false
Reputation:unknown
Preview:L..................F.@.. ....,.e%....'......,.e%................................P.O. .:i.....+00.../C:\.....................1.....NY.<..PROGRA~2.........O.INY.<....................V.......a.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....n.1.....NY.<..B2ELEC~1..V......NY.<NY.<...........................La.b.2. .e.l.e.c.t.r.o.n.i.c. .G.m.b.H.....j.1.....NY.<..B2CONT~1..R......NY.<NY.<..............................B.2. .C.o.n.t.r.o.l.C.e.n.t.e.r.....x.2.....}U.. .CONTRO~1.EXE..\......}U..NY.<....F.........................C.o.n.t.r.o.l.C.e.n.t.e.r...A.p.p...e.x.e.......................-.......~....................C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\ControlCenter.App.exe..V.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.b.2. .e.l.e.c.t.r.o.n.i.c. .G.m.b.H.\.B.2. .C.o.n.t.r.o.l.C.e.n.t.e.r.\.C.o.n.t.r.o.l.C.e.n.t.e.r...A.p.p...e.x.e...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.R.o.a.m.i.n.g.\.M.i.c.r.o.s.o.f.t.\.I.n.
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):107720
Entropy (8bit):6.231572329564986
Encrypted:false
SSDEEP:
MD5:343FB04807321967FF9FE761752CE4D4
SHA1:1B9D0D9083D76909F9D03439752DF27DAB7AA820
SHA-256:C120208DE8772D703BBE87A8580F995F49D808F1144E5495F263C54BEB5E536B
SHA-512:007931F523A09F3B4A0612568C4F91E11E4B298A881F2944064A760E7DABEECC5FEF55695B55CBD82E22F1E468CD9655F59410C1669B0E9D0EDCB184776E1A66
Malicious:false
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........t.w.'.w.'.w.'M..'.w.'M..'.w.'M..'.w.'..O'.w.'.w.'.w.'...'.w.'...'.w.'...'.w.'...'.w.'Rich.w.'........................PE..L...sg.[...........!................._....................................................@..........................^..`...\X..P...............................4...................................@I..@...............\............................text...{........................... ..`.rdata..@o.......p..................@..@.data...T....`.......R..............@....rsrc................b..............@..@.reloc..<#.......$...d..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):1260262
Entropy (8bit):5.823989104749377
Encrypted:false
SSDEEP:
MD5:D9217CF5B82766D0B1BC11630C64F83B
SHA1:F312484BFF53FD31FDF1771BCDC366C945687060
SHA-256:0D0495755A3F1DFE2FF3977971180B028C3AF488B544BC8D0506B7F654C8DB8D
SHA-512:00C4907AFD0FA279C6D898004EC5F2C3D7CB5DDC8AAA3AAB2196D201F64A056C4B8C40B8640BF33D67B2F6E87929F6B7A57A1B5FD57483B4A546A359EED61DCA
Malicious:false
Reputation:unknown
Preview:...@IXOS.@.....@..NY.@.....@.....@.....@.....@.....@......&.{D7F46775-46B0-4E89-8069-65CC2FA60046}..b2 ControlCenter..b2 ControlCenter.msi.@.....@..K..@.....@......ARPPRODUCTICON.exe..&.{B1B7EEAC-19DF-4A66-92D0-4A9FA0D4FD78}.....@.....@.....@.....@.......@.....@.....@.......@......b2 ControlCenter......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration...@<....@.....@.]....&.{F4E0226A-1877-4C25-BF3C-9DA3A77E9288}I.C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.License.dll.@.......@.....@.....@......&.{3642024A-7A59-4499-8599-6F2D0C684D04}).C:\Users\user\Documents\b2 ControlCenter\.@.......@.....@.....@......&.{4BD8BC03-7008-4D7A-B432-05B41111BC16};.C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\.@.......@.....@.....@......&.{9EBEE10F-D4FE-4567-B4EF-D65EE4AF68A0}T.C:\Program Files (x86)\b2 electronic GmbH\B2 ControlCenter\B2.ControlCenter.Core.dll.@.......
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.1665398905321513
Encrypted:false
SSDEEP:
MD5:5BEA53F9735E9D1DA55BAAF1887E0469
SHA1:37F99B7297C6AB403D9B975EFC782A71DFB03335
SHA-256:DB47F4E26A0CD7D867D241EA716F49E9614199B223DE7CEA6613E12E1EC280C6
SHA-512:650F54112A1755574ABBE7CF13F21772D19CD3C01CE2A3C8E7A3A5F11EEB8C98F60FED971D88A2D1D5DCBA824A1BFEB74CE006BEEDFC6012DC46D85E2857D27A
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
Category:dropped
Size (bytes):454234
Entropy (8bit):5.3561691487787195
Encrypted:false
SSDEEP:
MD5:5860D74E3509C3CFEDC5D29667822E08
SHA1:42338EA098E461FE7DCCBD529A6990B57DF0F6F4
SHA-256:54AA7373A4B5B4BE6C4EA992DC4292529543ADA47746A5FA79D19180D8F2348A
SHA-512:66B066A96A4184CA6DDF247BA84479871F00A2C7430E1DF3EE4E08F9063BA91AE589B611BFF7EAF97639355AD00D081044C4FCE5D735B909A55E97ECC7156F10
Malicious:false
Reputation:unknown
Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.3479815557270376
Encrypted:false
SSDEEP:
MD5:1EF86827A3A1F316499177AC87C6A75F
SHA1:BF94B1A156D736109851C5B619EE617E78F9C048
SHA-256:F78B923828B0160EA86E9D95E43754C120C8028BBA3793CA42659AC222B15A87
SHA-512:3B939E062738308B1FC648592DBA1489C4A0258C368365C4D1D520D07CE3567A12D9A164EDA2F9ACD0F0726C8119AFDDFF552673B04F1FC1ED57147F1EFD87F7
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):49152
Entropy (8bit):2.1379415668921378
Encrypted:false
SSDEEP:
MD5:855A8B1019E90CD6BF0776817603D559
SHA1:74916A0F978ADDC08D78ABB217A29055BBBE430A
SHA-256:EC6478A5570FB0504CA5656AE990EDECBDBBA010D0BA3207088C338BAEFD31A2
SHA-512:C9B2D240039F6909B05D58C3C7421AE07173AC90A561F0C84515BA473F7B00242F8150E5EF038BA1FDFD6B56DC8ADE7BE419E50030549A5756772A52CD9718D2
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):86016
Entropy (8bit):0.8861844572325469
Encrypted:false
SSDEEP:
MD5:9C60B6B408DE3F7C8D1DF8092C70F4CF
SHA1:A1AFE7684CB5A19E41834E532A14D747D0BEA450
SHA-256:099D088DEA136302F52D0EE2D0C6C8876A533AC9C6F93ADAEABAA71F7F239026
SHA-512:464325284C05B609073DD8BBCE2D8A62BA0A22ECA15553D55F451CA3F750724878BE2E2EA8AB9BC8F2218BE37DF098BDC7D37F435ADA1B04E0A40E47AA88AD37
Malicious:false
Reputation:unknown
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):32768
Entropy (8bit):0.07374520592730725
Encrypted:false
SSDEEP:
MD5:3AED385FC9EC0D73D7201FA4AAB4E61F
SHA1:85205E2DE30F3CDAA6527D69DC6B1485EF37F75A
SHA-256:1AF0C881E0304EFB70C9943EE3C49544C0B3299CFDEC040B7217961019866EAA
SHA-512:395F8624C159BA7B445C702F6CB65D5C0DE13CC3BA4CFD7EC3A2F5A8908AEE4ED41EF1DE892709B44CC6B781D62AE6144BD5465AF30A5B2CADD207B3997686AB
Malicious:false
Reputation:unknown
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Reputation:unknown
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.964162789533916
TrID:
  • Win32 Executable (generic) a (10002005/4) 99.96%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:b2 ControlCenter Setup V3.75.exe
File size:16'740'243 bytes
MD5:f02023e1e165fb92adaab5bf1ef98ed9
SHA1:9de491da46b50716d1b8164221c9b84a111fdfc2
SHA256:2a92ac98ae89f214cd10b1ca5eb26316bb588f73d5e0a2642c1768712ffb0aad
SHA512:4f0cc68d4065bf3fc0808734221894dacdc7689b27d8d8f316eb06b75064c0b37f9db8d4a3852375d7abf14966adcfb5b13aee7591f5ebc4d9bcf9af0418dcdf
SSDEEP:393216:sun+n8Laf969mYcbluvONQIvu81npIav8GPCX0g5qRC8:Eu+IoavONg8pj8cCkgIQ8
TLSH:68F62323A291902FE1B241324C6FAE7085AA7D339A75954BF250FF1D2EF05817D27F1A
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......j.5...[...[...[..H..%.[..H../.[..I..7.[..I....[.....-.[..I..l.[.....9.[...Z...[..H..n.[..H../.[...../.[..H../.[.Rich..[........
Icon Hash:497971328ce1634d
Entrypoint:0x45765a
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x5BA39BB1 [Thu Sep 20 13:08:01 2018 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:5
OS Version Minor:1
File Version Major:5
File Version Minor:1
Subsystem Version Major:5
Subsystem Version Minor:1
Import Hash:cbc19a820310308f17b0a7c562d044e0
Instruction
call 00007FCDC96329FBh
jmp 00007FCDC962A984h
push ebp
mov ebp, esp
xor edx, edx
mov eax, edx
cmp dword ptr [ebp+0Ch], eax
jbe 00007FCDC962AB13h
mov ecx, dword ptr [ebp+08h]
cmp word ptr [ecx], dx
je 00007FCDC962AB0Bh
inc eax
add ecx, 02h
cmp eax, dword ptr [ebp+0Ch]
jc 00007FCDC962AAF4h
pop ebp
ret
push ebp
mov ebp, esp
and dword ptr [004CDEC8h], 00000000h
sub esp, 10h
push ebx
xor ebx, ebx
inc ebx
or dword ptr [004C5AD0h], ebx
push 0000000Ah
call 00007FCDC964FD76h
test eax, eax
je 00007FCDC962AC14h
xor ecx, ecx
mov eax, ebx
mov dword ptr [004CDEC8h], ebx
cpuid
push esi
mov esi, dword ptr [004C5AD0h]
push edi
lea edi, dword ptr [ebp-10h]
or esi, 02h
mov dword ptr [edi], eax
mov dword ptr [edi+04h], ebx
mov dword ptr [edi+08h], ecx
mov dword ptr [edi+0Ch], edx
test dword ptr [ebp-08h], 00100000h
mov dword ptr [004C5AD0h], esi
je 00007FCDC962AB15h
or esi, 04h
mov dword ptr [004CDEC8h], 00000002h
mov dword ptr [004C5AD0h], esi
test dword ptr [ebp-08h], 10000000h
je 00007FCDC962AB15h
or esi, 08h
mov dword ptr [004CDEC8h], 00000003h
mov dword ptr [004C5AD0h], esi
push 00000007h
xor ecx, ecx
pop eax
cpuid
lea esi, dword ptr [ebp-10h]
mov dword ptr [esi], eax
mov dword ptr [esi+04h], ebx
mov dword ptr [esi+08h], ecx
mov dword ptr [esi+0Ch], edx
Programming Language:
  • [ C ] VS2012 UPD1 build 51106
  • [C++] VS2012 UPD1 build 51106
  • [RES] VS2012 UPD1 build 51106
  • [LNK] VS2012 UPD1 build 51106
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0xc23280xf0.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0xd00000x4cc90.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x11d0000xa574.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x969b00x38.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xa9ad00x40.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x960000x600.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xc1c7c0xe0.rdata
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x947890x94800764b34cabee1111c9e11c8f836aebafbFalse0.5110446917087542data6.53979245548133IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x960000x2e3380x2e4007989312225f01ce65374248a3e73a557False0.34926097972972975data4.588598297519254IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0xc50000xad900x28001ac52732b5e747734a833e523cd8f27fFalse0.2876953125data4.418143406666556IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc0xd00000x4cc900x4ce00027cc733ba40e32688267260321d3840False0.33816692073170734data6.561400285457568IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x11d0000x27b660x27c00d11bf51446bb40b38f82ba6ce1f57dc4False0.1575213738207547data2.4787558945854284IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
GIF0xd0dcc0x33a7GIF image data, version 89a, 350 x 6240.9106859260379642
GIF0xd41740x339fGIF image data, version 89a, 350 x 624EnglishUnited States0.9129020052970109
PNG0xd75140x39edPNG image data, 360 x 150, 8-bit/color RGBA, non-interlaced0.9975723244992919
PNG0xdaf040x2fc9PNG image data, 240 x 227, 8-bit/color RGBA, non-interlaced0.9968119022316685
RT_BITMAP0xdded00x14220Device independent bitmap graphic, 220 x 370 x 8, image size 814000.34390764454792394
RT_BITMAP0xf20f00x1b5cDevice independent bitmap graphic, 180 x 75 x 4, image size 69000.18046830382638493
RT_BITMAP0xf3c4c0x38e4Device independent bitmap graphic, 180 x 75 x 8, image size 135000.26689096402087337
RT_BITMAP0xf75300x1238Device independent bitmap graphic, 60 x 60 x 8, image size 36000.23499142367066894
RT_BITMAP0xf87680x6588Device independent bitmap graphic, 161 x 152 x 8, image size 24928, resolution 3796 x 3796 px/m, 256 important colors0.3035934133579563
RT_BITMAP0xfecf00x11f88Device independent bitmap graphic, 161 x 152 x 24, image size 73568, resolution 3780 x 3780 px/m0.12790729268557766
RT_ICON0x110c780x468Device independent bitmap graphic, 16 x 32 x 32, image size 10240.21808510638297873
RT_ICON0x1110e00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 40960.099906191369606
RT_ICON0x1121880x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 92160.06109958506224066
RT_ICON0x1147300x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 6400.35618279569892475
RT_ICON0x114a180x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 6400.42473118279569894
RT_DIALOG0x114d000x1cedata0.48917748917748916
RT_DIALOG0x114ed00x266data0.4527687296416938
RT_DIALOG0x1151380x2b0data0.438953488372093
RT_DIALOG0x1153e80x54data0.6904761904761905
RT_DIALOG0x11543c0x34data0.8846153846153846
RT_DIALOG0x1154700xd6data0.6495327102803738
RT_DIALOG0x1155480x114data0.5036231884057971
RT_DIALOG0x11565c0xd6data0.5841121495327103
RT_DIALOG0x1157340x246data0.4690721649484536
RT_DIALOG0x11597c0x3c8data0.4194214876033058
RT_DIALOG0x115d440x14edata0.5359281437125748
RT_DIALOG0x115e940x1e8data0.49385245901639346
RT_DIALOG0x11607c0x1c6data0.5286343612334802
RT_DIALOG0x1162440x1eedata0.49190283400809715
RT_DIALOG0x1164340x7cdata0.7580645161290323
RT_DIALOG0x1164b00x3bcdata0.4372384937238494
RT_DIALOG0x11686c0x158data0.5581395348837209
RT_DIALOG0x1169c40x1dadata0.5168776371308017
RT_DIALOG0x116ba00x10adata0.6015037593984962
RT_DIALOG0x116cac0xdedata0.6441441441441441
RT_DIALOG0x116d8c0x1d4data0.5085470085470085
RT_DIALOG0x116f600x1dcdata0.5210084033613446
RT_DIALOG0x11713c0x294data0.48787878787878786
RT_STRING0x1173d00x160dataEnglishUnited States0.5340909090909091
RT_STRING0x1175300x23edataEnglishUnited States0.40418118466898956
RT_STRING0x1177700x378dataEnglishUnited States0.4222972972972973
RT_STRING0x117ae80x252dataEnglishUnited States0.4393939393939394
RT_STRING0x117d3c0x1f4dataEnglishUnited States0.442
RT_STRING0x117f300x66adataEnglishUnited States0.3617539585870889
RT_STRING0x11859c0x366dataEnglishUnited States0.41379310344827586
RT_STRING0x1189040x27edataEnglishUnited States0.4561128526645768
RT_STRING0x118b840x518dataEnglishUnited States0.39800613496932513
RT_STRING0x11909c0x882dataEnglishUnited States0.3002754820936639
RT_STRING0x1199200x23edataEnglishUnited States0.45121951219512196
RT_STRING0x119b600x3badataEnglishUnited States0.3280922431865828
RT_STRING0x119f1c0x12cdataEnglishUnited States0.5266666666666666
RT_STRING0x11a0480x4adataEnglishUnited States0.6756756756756757
RT_STRING0x11a0940xdadataEnglishUnited States0.6100917431192661
RT_STRING0x11a1700x110dataEnglishUnited States0.5845588235294118
RT_STRING0x11a2800x20adataEnglishUnited States0.4521072796934866
RT_STRING0x11a48c0xbaMatlab v4 mat-file (little endian) P, numeric, rows 0, columns 0EnglishUnited States0.5860215053763441
RT_STRING0x11a5480xa8dataEnglishUnited States0.6607142857142857
RT_STRING0x11a5f00x12adataEnglishUnited States0.5201342281879194
RT_STRING0x11a71c0x422dataEnglishUnited States0.2741020793950851
RT_STRING0x11ab400x5c2dataEnglishUnited States0.37720488466757124
RT_STRING0x11b1040x40dataEnglishUnited States0.671875
RT_STRING0x11b1440xcaadataEnglishUnited States0.2313386798272671
RT_STRING0x11bdf00x284dataEnglishUnited States0.4363354037267081
RT_GROUP_ICON0x11c0740x30data0.8125
RT_GROUP_ICON0x11c0a40x14data1.25
RT_GROUP_ICON0x11c0b80x14data1.2
RT_VERSION0x11c0cc0x418data0.43416030534351147
RT_MANIFEST0x11c4e40x52aXML 1.0 document, ASCII text, with CRLF line terminators0.46520423600605143
RT_MANIFEST0x11ca100x280XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.553125
DLLImport
COMCTL32.dll
KERNEL32.dllMoveFileW, LocalFree, FormatMessageW, GetSystemInfo, MulDiv, RaiseException, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LoadLibraryExW, GetVersion, GetLocalTime, GetFileAttributesW, GetCurrentDirectoryW, FileTimeToLocalFileTime, GetFileTime, GetSystemDefaultUILanguage, GlobalAlloc, GlobalFree, FlushFileBuffers, VirtualQuery, IsBadReadPtr, GetDiskFreeSpaceExW, GetDriveTypeW, GetCurrentThread, InterlockedExchange, LoadLibraryExA, GetModuleHandleW, GetProcAddress, GetSystemDirectoryA, LoadLibraryA, GetLastError, SetLastError, GetPrivateProfileStringW, GetFileSize, CloseHandle, CreateFileMappingW, MapViewOfFile, UnmapViewOfFile, lstrlenA, MultiByteToWideChar, WideCharToMultiByte, ReadFile, SetFilePointer, WriteFile, HeapAlloc, GetSystemTimeAsFileTime, SetFileAttributesW, FindNextFileW, FindFirstFileW, FindClose, CreateDirectoryW, CompareFileTime, VerLanguageNameW, GetUserDefaultLangID, GetSystemDefaultLangID, lstrcmpiW, lstrcmpW, IsValidLocale, GetLocaleInfoW, lstrcpyA, ExitThread, GetExitCodeProcess, GetCommandLineW, LoadLibraryW, FreeLibrary, FreeResource, lstrcmpA, SystemTimeToFileTime, ResetEvent, SetEvent, FindResourceExW, SetFileTime, OpenProcess, GetProcessTimes, ReadConsoleW, WriteConsoleW, SetStdHandle, SetFilePointerEx, GetConsoleMode, CompareStringA, CompareStringW, lstrcatW, GetVersionExW, InterlockedDecrement, InterlockedIncrement, CreateEventW, QueryPerformanceFrequency, GetTempFileNameW, CopyFileW, GetTickCount, GetExitCodeThread, CreateThread, FindResourceW, GlobalUnlock, GlobalLock, SizeofResource, LockResource, LoadResource, lstrcpyW, SetErrorMode, GetTempPathW, ExpandEnvironmentStringsW, CreateFileW, MoveFileExW, WriteProcessMemory, VirtualProtectEx, GetWindowsDirectoryW, GetSystemDirectoryW, FlushInstructionCache, SetThreadContext, GetThreadContext, CreateProcessW, ResumeThread, TerminateProcess, ExitProcess, GetCurrentProcess, Sleep, WaitForSingleObject, DuplicateHandle, RemoveDirectoryW, DeleteFileW, SetCurrentDirectoryW, lstrlenW, lstrcpynW, GetModuleFileNameW, GetProcessHeap, HeapFree, GetConsoleCP, GetTimeFormatW, GetDateFormatW, OutputDebugStringW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCurrentProcessId, QueryPerformanceCounter, GetFileType, HeapReAlloc, GetStartupInfoW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetStringTypeW, GetCPInfo, GetOEMCP, GetACP, IsValidCodePage, GetCurrentThreadId, HeapSize, GetModuleHandleExW, GetStdHandle, GetFullPathNameW, IsProcessorFeaturePresent, IsDebuggerPresent, RtlUnwind, LCMapStringW, DecodePointer, EncodePointer
USER32.dllGetMessageW, TranslateMessage, DispatchMessageW, PostMessageW, DefWindowProcW, PostQuitMessage, RegisterClassW, CreateWindowExW, SetTimer, KillTimer, LoadCursorW, LoadIconW, wsprintfW, PeekMessageW, MsgWaitForMultipleObjects, GetDesktopWindow, ShowWindow, DialogBoxIndirectParamW, EndDialog, GetDlgItem, SetWindowTextW, SetWindowPos, CharPrevW, wvsprintfW, LoadImageW, CreateDialogParamW, MoveWindow, GetParent, GetWindowTextW, SetCursor, GetWindow, GetDlgItemTextW, SetFocus, SetForegroundWindow, SetActiveWindow, SetDlgItemTextW, FindWindowW, SubtractRect, IntersectRect, SetRect, GetWindowDC, GetSysColorBrush, GetSysColor, GetDC, GetSystemMetrics, GetDlgCtrlID, CreateDialogIndirectParamW, ExitWindowsEx, CharUpperW, wsprintfA, CallWindowProcW, DrawIcon, DrawTextW, UpdateWindow, InvalidateRect, SetPropW, GetPropW, RemovePropW, MapWindowPoints, DrawFocusRect, CopyRect, InflateRect, EnumChildWindows, GetClassNameW, MapDialogRect, RegisterClassExW, MonitorFromPoint, CharNextW, IsDialogMessageW, FindWindowExW, ScreenToClient, MessageBoxW, GetWindowRect, EnableWindow, SendDlgItemMessageW, DestroyWindow, IsWindow, SendMessageW, WaitForInputIdle, SetWindowLongW, GetWindowLongW, GetClientRect, EndPaint, BeginPaint, ReleaseDC, FillRect
GDI32.dllCreateHalftonePalette, GetDIBColorTable, SelectPalette, RealizePalette, GetSystemPaletteEntries, CreatePalette, CreateFontW, SetTextColor, SetBkMode, GetDeviceCaps, CreateSolidBrush, GetObjectW, TranslateCharsetInfo, CreateFontIndirectW, SetStretchBltMode, StretchBlt, SelectObject, DeleteDC, CreateDIBitmap, CreateCompatibleDC, BitBlt, DeleteObject, GetStockObject, CreateCompatibleBitmap, CreateDCW, CreatePatternBrush, GetTextExtentPoint32W, RestoreDC, SaveDC, DeleteMetaFile, CreateBitmap, CreateRectRgn, PatBlt, PlayMetaFile, SelectClipRgn, SetBkColor, SetMapMode, SetMetaFileBitsEx, SetPixel, SetViewportExtEx, SetViewportOrgEx, SetWindowExtEx, SetWindowOrgEx, UnrealizeObject
ADVAPI32.dllRegSetValueExW, RegOpenKeyExW, RegOpenKeyW, RegOverridePredefKey, LookupPrivilegeValueW, AdjustTokenPrivileges, GetTokenInformation, FreeSid, EqualSid, AllocateAndInitializeSid, OpenThreadToken, OpenProcessToken, SetEntriesInAclW, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, CreateWellKnownSid, RegQueryInfoKeyW, RegEnumKeyExW, RegDeleteKeyW, RegEnumValueW, RegDeleteValueW, RegQueryValueExW, RegCreateKeyExW, RegCloseKey
SHELL32.dllCommandLineToArgvW, ShellExecuteW, SHBrowseForFolderW, SHGetPathFromIDListW, SHGetMalloc, ShellExecuteExW, SHGetFolderPathW
ole32.dllCoInitializeSecurity, CoInitialize, CoUninitialize, CreateStreamOnHGlobal, CoTaskMemRealloc, CoTaskMemAlloc, CLSIDFromProgID, CoCreateGuid, CoCreateInstance, CoTaskMemFree
OLEAUT32.dllSysAllocString, SysStringLen, VarBstrCmp, UnRegisterTypeLib, RegisterTypeLib, LoadTypeLib, SysStringByteLen, SysAllocStringByteLen, VarBstrCat, VarBstrFromDate, VariantClear, VariantChangeType, GetErrorInfo, VarUI4FromStr, SysReAllocStringLen, SysAllocStringLen, SysFreeString, SystemTimeToVariantTime
SHLWAPI.dllPathFileExistsW
RPCRT4.dllUuidToStringW, RpcStringFreeW, UuidCreate
gdiplus.dllGdipCreateBitmapFromFile, GdipCreateBitmapFromStreamICM, GdipCreateBitmapFromResource, GdipCreateFromHDC, GdipDeleteGraphics, GdipSetInterpolationMode, GdipDrawImageRectI, GdipGetImageWidth, GdipGetImageHeight, GdipAlloc, GdipFree, GdiplusStartup, GdipCloneImage, GdipCreateBitmapFromStream, GdipDisposeImage
Language of compilation systemCountry where language is spokenMap
EnglishUnited States