Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
USB-DRIVERS-ALL-11-14-13.exe

Overview

General Information

Sample name:USB-DRIVERS-ALL-11-14-13.exe
Analysis ID:1546388
MD5:0cc5d1c6eb22a1c08ff1bf65c7802f32
SHA1:98b2ce2711c43b184ffc2146eec2f01c1bb5ab6e
SHA256:be3b6f84d3749adf2742a516efe65dc53425b744ff052486a39ede4503ab0591

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

OS version to string mapping found (often used in BOTs)
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files

Classification

  • System is w10x64
  • USB-DRIVERS-ALL-11-14-13.exe (PID: 6848 cmdline: "C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exe" MD5: 0CC5D1C6EB22A1C08FF1BF65C7802F32)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-10-31T20:37:00.816852+010020229301A Network Trojan was detected52.149.20.212443192.168.2.549704TCP
2024-10-31T20:37:40.083884+010020229301A Network Trojan was detected52.149.20.212443192.168.2.549911TCP

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: c:\develo~1\cdm2_2_4\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdb source: ftserui2.dll
Source: Binary string: C:\DEVELO~1\ftdi.whq\BUS\objfre\i386\ftdibus.pdb source: ftdibus.sys
Source: Binary string: c:\develo~1\cdm2_2_4\devices\ftser2k\objfre_wnet_x86\i386\ftser2k.pdb_ source: ftser2k.sys
Source: Binary string: c:\dev\development\fixedfunction\cp210x\drivers\vcp\windows_2k_xp_s2k3_vista_7\objfre_wnet_amd64\amd64\silabser.pdb source: silabser.sys
Source: Binary string: c:\develo~1\cdm2_2_4\devices\ftser2k\objfre_wnet_amd64\amd64\ftser2k.pdb source: ftser2k.sys
Source: Binary string: c:\develo~1\cdm2_2_4\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdb source: ftcserco.dll
Source: Binary string: c:\Development\cdm2_2_4\FTBUSUI\x64\Release\FTBUSUI.pdb source: ftbusui.dll
Source: Binary string: c:\Development\cdm2_2_4\FTBUSUI\x64\Release\FTBUSUI.pdb! source: ftbusui.dll
Source: Binary string: C:\Development\Windows\PropertyPage\objfre\i386\ftserui2.pdb source: ftserui2.dll
Source: Binary string: c:\develo~1\cdm2_2_4\d2xx\d2xx\objfre_wnet_amd64\amd64\FTDIBUS.pdb source: ftdibus.sys
Source: Binary string: c:\develo~1\cdm2_2_4\coinst\ftcserco\objfre_wnet_x86\i386\ftcserco.pdb source: ftcserco.dll
Source: Binary string: c:\Development\cdm2_2_4\FTLang\Release\FTLang.pdbp* source: ftlang.dll
Source: Binary string: c:\develo~1\cdm2_2_4\d2xx\d2xx\objfre_wnet_x86\i386\FTDIBUS.pdb-o source: ftdibus.sys
Source: Binary string: C:\98DDK\src\ftdi.800\FTSERMOU\obj\i386\ftsermou.pdb source: FTSERMOU.VXD
Source: Binary string: DpInst.pdb source: CP210xVCPInstaller_32_Bit.exe, CP210xVCPInstaller_64_Bit.exe
Source: Binary string: DpInst.pdbp source: CP210xVCPInstaller_32_Bit.exe
Source: Binary string: WdfCoInstaller01009.pdbE3 source: WdfCoInstaller01009.dll
Source: Binary string: c:\develo~1\cdm2_2_4\d2xx\d2xx\objfre_wnet_x86\i386\FTDIBUS.pdb source: ftdibus.sys
Source: Binary string: c:\Development\cdm2_2_4\FTLang\Release\FTLang.pdb source: ftlang.dll
Source: Binary string: WdfCoInstaller01009.pdb source: WdfCoInstaller01009.dll
Source: Binary string: C:\DEVELO~1\ftdi.whq\DEVICES\SERIAL\objfre\i386\ftser2k.pdb source: ftser2k.sys
Source: Binary string: c:\dev\development\fixedfunction\cp210x\drivers\serialenumerationfilter\windows_xp_s2k3_vista_7\objfre_wnet_amd64\amd64\silabenm.pdb source: silabenm.sys
Source: Binary string: c:\develo~1\cdm2_2_4\devices\ftser2k\objfre_wnet_x86\i386\ftser2k.pdb source: ftser2k.sys
Source: Binary string: c:\develo~1\cdm2_2_4\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdbH source: ftserui2.dll
Source: Binary string: c:\Development\cdm2_2_4\d2xxdll\x64\Release\FTD2XX64.pdb source: ftd2xx64.dll
Source: Binary string: c:\Development\cdm2_2_4\d2xxdll\Release\FTD2XX.pdb source: ftd2xx.dll
Source: Binary string: DpInst.pdbH source: CP210xVCPInstaller_64_Bit.exe
Source: Binary string: c:\develo~1\cdm2_2_4\pp\ftserui2\objfre_wnet_x86\i386\ftserui2.pdb source: ftserui2.dll
Source: Binary string: c:\dev\development\fixedfunction\cp210x\drivers\serialenumerationfilter\windows_xp_s2k3_vista_7\objchk_wxp_x86\i386\silabenm.pdb source: silabenm.sys
Source: Binary string: c:\develo~1\cdm2_2_4\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdbH source: ftcserco.dll
Source: Binary string: c:\dev\development\fixedfunction\cp210x\drivers\vcp\windows_2k_xp_s2k3_vista_7\objfre_wxp_x86\i386\silabser.pdb source: silabser.sys
Source: Binary string: c:\Development\cdm2_2_4\FTLang\x64\Release\FTLang.pdb source: ftlang.dll
Source: Binary string: c:\Development\cdm2_2_4\FTBUSUI\Release\FTBUSUI.pdb source: ftbusui.dll
Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 52.149.20.212:443 -> 192.168.2.5:49704
Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 52.149.20.212:443 -> 192.168.2.5:49911
Source: USB_FTDI_Setup.exeString found in binary or memory: http://nsis.sf.net/NSIS_Error
Source: USB_FTDI_Setup.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: USB-DRIVERS-ALL-11-14-13.exeString found in binary or memory: http://www.winzip.com
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: Resource name: RT_STRING type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 0.101
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: FTSERIAL.SYSBinary string: \Device\Ftdiport_Com_0\FTDIBUS\FTDIBUS&VID_0403+PID_8373+F0000000A&0000U
Source: ftdibus.sysBinary string: ParentIdPrefixCompositeSubKeyCompositeDriverInterface\Registry\Machine\SYSTEM\CurrentControlSet\Enum\USBPID_FTDIBUS\VID_&PID_FTDIBUS\COMPORT&VID_FTDIBUS\0000\DosDevices\Ftdiport_Com_0\Device\Ftdiport_Com_0\COMPortNameENUM\0000Enum\FriendlyName) (DeviceDescRtlIsNtDdiVersionAvailable
Source: FTSERIAL.SYSBinary string: \DosDevices\FTSERI-0\Device\FTSERI-0U
Source: silabser.sysBinary string: \Device\Silabser
Source: ftdibus.sysBinary string: \Device\Ftdiport_Com_0
Source: ftser2k.sysBinary string: \Device\VCP
Source: ftser2k.sysBinary string: @\Device\VCPU
Source: ftdibus.sysBinary string: \Device\FTE2USB0\REGISTRY\Machine\System\CurrentControlSet\SERVICES\FTDIBUS\ParametersU
Source: silabser.sysBinary string: SerialRelinquishPowerPolicy%ws%d\Device\Silabser-->SerialEvtDeviceAdd
Source: FTSERIAL.SYSBinary string: \Device\FTSERI-0U
Source: ftdibus.sysBinary string: \Device\Ftdiport_Com_0\DosDevices\Ftdiport_Com_0AFTDIBUS\0000U
Source: FTSERIAL.SYSBinary string: \Device\Ftdiport_Com_0\FTDIBUS\1111U
Source: ftser2k.sysBinary string: EmulationModeLatencyTimerTerminateDelayMinWriteTimeoutMinReadTimeoutTxBufferRxBufferConfigDataSERIALCOMMDosDevices\IdentifierPortNameSerialSkipExternalNaming\Device\VCPSerialRelinquishPowerPolicy*PNP0501*PNP0502MultiportDevice
Source: classification engineClassification label: clean1.winEXE@1/0@0/0
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: CP210xVCPInstaller_32_Bit.exeString found in binary or memory: ERROR: (Error code 0x%X.) (Error code 0x%X: %s)%02d/%02d/%04d %02d:%02d:%02dNon-Interactive Windows StationInteractive Windows StationFailed to check if running under Local System AccountRunning under Local System AccountArchitecture: X86.Suite: 0x%04x, Product Type: %uService Pack: %u.%uPlatform ID: %u (%s)9XNTVersion: %u.%u.%u %sProduct Version %s.****************************************Failed to delete 'Add or Remove Programs' entry '%s'.User cancelled uninstall of driver package '%s'Access denied to Non-admin user to install/uninstall driver package.System requires 64-bit version of DPInst.exe.DPInst.exe not supported on current OS.Requested language 0x%X is not supported on current systemDescriptor (DPInst.xml) does not support requested language 0x%X.Will read descriptor(DPInst.xml) elements in language 0x%X, but some or all of the other elements might be in the UI default language 0x%X.Will read descriptor(DPInst.xml) elements in language 0x%X.Running with language 0x%X.Current configuration does not support UI language 0x%X.Will enable language 0x%X although not listed in descriptor.User UI Language is 0x%X.Invalid path '%ws'Install option set: using scan hardware display mode. Will only display successfull installs or failures.Install option set: test wizard cycling through all finish pages.Install option set: uninstall will be set to delete driver binaries.Install option set: Install all driver packages or none.Install option set: Suppress Add or Remove Programs entries.Install option set: Suppress pre-install of Plug and Play drivers if no matching devices are present.Install option set: Force install if driver is not better.Install option set: Prompt if driver is not better.Install option set: create user uninstall script file '%s'.Install option set: Suppressing EULA.Install option set: legacy mode on.Install option set: Running in quiet mode. Suppressing Wizard and OS popups.Install option set: Suppressing Wizard but no OS popups.Install option refused: can't test wizard because quiet mode enabled.Install option refused: 'Scan Hardware Display' will be ignored because not running in 'Scan Hardware Mode'.Install option refused: Can't run in Quiet mode, UI will be shown because a EULA is required and not suppressed!Install option refused: Can't run in Quiet mode, command to prompt user in case driver is not better is set!Install option refused: will not force install if driver is not better because of command to prompt if driver is not better.No valid '%s' file provided.Running on path '%ws'Invalid uninstall script file '%s', invalid entry '%s'.Invalid uninstall script file '%s', missing hash after ID entry.Invalid uninstall script file '%s', missing path after USCRIPT entry.Invalid uninstall script file '%s', missing path after INF entry.IDUSCRIPTINFUninstall script self-reference. Script '%s' already uninstalled.Invalid uninstall script file: '%s'Machine has to be rebooted to complete uninstall.Starting uninstall of script '%ws'St
Source: CP210xVCPInstaller_32_Bit.exeString found in binary or memory: @Error encountered while adding reference of installer '%s' to driver storeError encountered while setting installer information for driver storeUnknown ProductUnknown ManufacturerUnknown Display NameParameter is NULL.RETURN: DriverPackageGetPathW (0x%X)ENTER: DriverPackageGetPathWOne or more files referenced by '%s' cannot be found in the package.Unsigned driver. Possibly rejected by user.Invalid signature. Possibly rejected by user.Could not delete driver store entry '%s'.Failed to add catalog file for '%s'.Driver package is already preinstalled '%s'.The driver package type of %s is not supported.Could not remove driver store entry '%s'.Driver Store entry '%s' removed.Successfully removed '%s' from reference list of driver store entry '%s'Implementation error: Invalid Type %u.Installing INF file '%s' of Type %u.Could not get name of the inf file.Could not remove '%s' from reference list of driver store entry '%s'Could not get Type property for driver package.Installation completed with code 0x%X.Can't repair driver packages from the INF directory.The INSTALLERINFO structure passed in by the caller was non-NULL, but one or more fields of the structure was NULL or an empty string.Successfully deleted properties for driver store entry '%s'.Could not delete properties for driver store entry '%s'.Successfully deleted driver store entry '%s'.Installing INF file '%s' (Plug and Play).Can't preinstall and then install driver packages from the INF directory.DRIVER_PACKAGE_LEGACY_MODE flag set but not supported on Plug and Play driver on VISTA. Flag will be ignored.Successfully re-added '%s' to reference list of driver store entry '%s'Could not re-add '%s' to reference list of driver store entry '%s'Uninstall completed.Uninstall: Invalid Driver Store entry '%s'.Driver store entry '%s' removed.Best effort to delete driver package files copied to system...Error occurred while uninstalling driver package '%s'Uninstalling driver package %s...Could not remove the reference of driver '%s' from driver storeWill not uninstall because other Application depend on this package %s.Could not get Type property for driver package '%s'.Could not get INF PATH property for driver package '%s'.No driver store entry for '%s' found.An error occurred while uninstalling driver package '%s'Cannot uninstall inbox driver package '%s'Could not verify if there are any applications that are still dependent on driver '%s'.Could not remove the reference of application '%s' from driver '%s'RETURN: DriverPackagePreinstallW (0x%X)%s is preinstalled.ENTER: DriverPackagePreinstallWRETURN: DriverPackageInstallW (0x%X)ENTER: DriverPackageInstallWRETURN: DriverPackageUninstallW (0x%X)ENTER: DriverPackageUninstallWl
Source: CP210xVCPInstaller_32_Bit.exeString found in binary or memory: Pronto all'uso/Installazione non riuscita (driver non firmato)0Installazione non riuscita (certificato scaduto)
Source: CP210xVCPInstaller_32_Bit.exeString found in binary or memory: re.4Guiden Installation af enhedsdriver blev annulleret.-Installationen mislykkedes (ugyldig signatur)eEs wird bereits der beste Ger
Source: CP210xVCPInstaller_32_Bit.exeString found in binary or memory: stata rilevata nessuna periferica da aggiornare.1Non necessario (nessuna periferica da aggiornare)8Annullamento installazione driver in corso. Attendere...5Installazione guidata driver di periferica annullata.-Installazione non riuscita (firma non valida):
Source: CP210xVCPInstaller_32_Bit.exeString found in binary or memory: FileDescriptionTreiberpaket-Installationsprogramm(
Source: CP210xVCPInstaller_32_Bit.exeString found in binary or memory: ProductNameTreiberpaket-Installationsprogramm (DPInst),
Source: CP210xVCPInstaller_64_Bit.exeString found in binary or memory: ,Software\Policies\Microsoft\Windows\DriverInstall\RestrictionsAllowUserDeviceClasses DummyWindowWindow_CaptionRunAs****************************************Failed to get command line.Command Line: '%s'DPInst is a multi-lingual binary.DPInst is not multi-lingual.The module name was too long.There was an error getting the module name.Failed to initialize MUI or Multi-Lingual language support.Title: %s.Option to dump log info on console not available under Windows 2000. Ignoring the option.Option set: dumping log info to console.Failed to set option to dump log info to console.Failed to set the current working directory to: '%ws'Current working directory: '%ws'Returning with code 0x%XRunning on path '%ws'Invalid path '%ws'No valid '%s' file provided.Install option refused: will not force install if driver is not better because of command to prompt if driver is not better.Install option refused: Can't run in Quiet mode, command to prompt user in case driver is not better is set!Install option refused: Can't run in Quiet mode, UI will be shown because a EULA is required and not suppressed!Install option refused: 'Scan Hardware Display' will be ignored because not running in 'Scan Hardware Mode'.Install option refused: can't test wizard because quiet mode enabled.Install option set: Suppressing Wizard but no OS popups.Install option set: Running in quiet mode. Suppressing Wizard and OS popups.Install option set: legacy mode on.Install option set: Suppressing EULA.Install option set: create user uninstall script file '%s'.Install option set: Prompt if driver is not better.Install option set: Force install if driver is not better.Install option set: Suppress pre-install of Plug and Play drivers if no matching devices are present.Install option set: Suppress Add or Remove Programs entries.Install option set: Install all driver packages or none.Install option set: uninstall will be set to delete driver binaries.Install option set: test wizard cycling through all finish pages.Install option set: using scan hardware display mode. Will only display successfull installs or failures.Uninstall option set: Suppressing Wizard but no OS popups.Uninstall option set: Running in quiet mode. Suppressing Wizard and OS popups.Uninstall command: uninstall Inf '%ws'Uninstall command: uninstall script '%ws'Uninstall option set: if driver was installed, will make best effort to delete driver binaries.User cancelled uninstall.Starting uninstall of '%ws'Starting uninstall of script '%ws'Machine has to be rebooted to complete uninstall.Uninstall script self-reference. Script '%s' already uninstalled.Invalid uninstall script file: '%s'Uninstall script file '%s' not found.Failed to delete 'Add or Remove Programs' entry '%s'.User cancelled uninstall of driver package '%s'ERROR: Access denied to Non-admin user to install/uninstall driver package.DPInst.exe not supported on current OS.User UI Language is 0x%X.Will enable language 0x%X although not listed in descriptor.Current confi
Source: CP210xVCPInstaller_64_Bit.exeString found in binary or memory: Pronto all'uso/Installazione non riuscita (driver non firmato)0Installazione non riuscita (certificato scaduto)
Source: CP210xVCPInstaller_64_Bit.exeString found in binary or memory: re.4Guiden Installation af enhedsdriver blev annulleret.-Installationen mislykkedes (ugyldig signatur)eEs wird bereits der beste Ger
Source: CP210xVCPInstaller_64_Bit.exeString found in binary or memory: stata rilevata nessuna periferica da aggiornare.1Non necessario (nessuna periferica da aggiornare)8Annullamento installazione driver in corso. Attendere...5Installazione guidata driver di periferica annullata.-Installazione non riuscita (firma non valida):
Source: CP210xVCPInstaller_64_Bit.exeString found in binary or memory: FileDescriptionTreiberpaket-Installationsprogramm(
Source: CP210xVCPInstaller_64_Bit.exeString found in binary or memory: ProductNameTreiberpaket-Installationsprogramm (DPInst),
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeFile read: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: sfc.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: networkexplorer.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: samlib.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: drprov.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: winsta.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: ntlanman.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: davclnt.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: davhlpr.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: cscapi.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: dlnashext.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: playtodevice.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: devdispitemprovider.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: mmdevapi.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: devobj.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: wpdshext.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: portabledeviceapi.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: audiodev.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: wmvcore.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: wmasf.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: mfperfhelper.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: thumbcache.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32Jump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeAutomated click: OK
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeAutomated click: OK
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeAutomated click: OK
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeAutomated click: OK
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeAutomated click: OK
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeAutomated click: OK
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeAutomated click: OK
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeAutomated click: OK
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: USB-DRIVERS-ALL-11-14-13.exeStatic file information: File size 7715840 > 1048576
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: Raw size of _winzip_ is bigger than: 0x100000 < 0x740200
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: c:\develo~1\cdm2_2_4\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdb source: ftserui2.dll
Source: Binary string: C:\DEVELO~1\ftdi.whq\BUS\objfre\i386\ftdibus.pdb source: ftdibus.sys
Source: Binary string: c:\develo~1\cdm2_2_4\devices\ftser2k\objfre_wnet_x86\i386\ftser2k.pdb_ source: ftser2k.sys
Source: Binary string: c:\dev\development\fixedfunction\cp210x\drivers\vcp\windows_2k_xp_s2k3_vista_7\objfre_wnet_amd64\amd64\silabser.pdb source: silabser.sys
Source: Binary string: c:\develo~1\cdm2_2_4\devices\ftser2k\objfre_wnet_amd64\amd64\ftser2k.pdb source: ftser2k.sys
Source: Binary string: c:\develo~1\cdm2_2_4\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdb source: ftcserco.dll
Source: Binary string: c:\Development\cdm2_2_4\FTBUSUI\x64\Release\FTBUSUI.pdb source: ftbusui.dll
Source: Binary string: c:\Development\cdm2_2_4\FTBUSUI\x64\Release\FTBUSUI.pdb! source: ftbusui.dll
Source: Binary string: C:\Development\Windows\PropertyPage\objfre\i386\ftserui2.pdb source: ftserui2.dll
Source: Binary string: c:\develo~1\cdm2_2_4\d2xx\d2xx\objfre_wnet_amd64\amd64\FTDIBUS.pdb source: ftdibus.sys
Source: Binary string: c:\develo~1\cdm2_2_4\coinst\ftcserco\objfre_wnet_x86\i386\ftcserco.pdb source: ftcserco.dll
Source: Binary string: c:\Development\cdm2_2_4\FTLang\Release\FTLang.pdbp* source: ftlang.dll
Source: Binary string: c:\develo~1\cdm2_2_4\d2xx\d2xx\objfre_wnet_x86\i386\FTDIBUS.pdb-o source: ftdibus.sys
Source: Binary string: C:\98DDK\src\ftdi.800\FTSERMOU\obj\i386\ftsermou.pdb source: FTSERMOU.VXD
Source: Binary string: DpInst.pdb source: CP210xVCPInstaller_32_Bit.exe, CP210xVCPInstaller_64_Bit.exe
Source: Binary string: DpInst.pdbp source: CP210xVCPInstaller_32_Bit.exe
Source: Binary string: WdfCoInstaller01009.pdbE3 source: WdfCoInstaller01009.dll
Source: Binary string: c:\develo~1\cdm2_2_4\d2xx\d2xx\objfre_wnet_x86\i386\FTDIBUS.pdb source: ftdibus.sys
Source: Binary string: c:\Development\cdm2_2_4\FTLang\Release\FTLang.pdb source: ftlang.dll
Source: Binary string: WdfCoInstaller01009.pdb source: WdfCoInstaller01009.dll
Source: Binary string: C:\DEVELO~1\ftdi.whq\DEVICES\SERIAL\objfre\i386\ftser2k.pdb source: ftser2k.sys
Source: Binary string: c:\dev\development\fixedfunction\cp210x\drivers\serialenumerationfilter\windows_xp_s2k3_vista_7\objfre_wnet_amd64\amd64\silabenm.pdb source: silabenm.sys
Source: Binary string: c:\develo~1\cdm2_2_4\devices\ftser2k\objfre_wnet_x86\i386\ftser2k.pdb source: ftser2k.sys
Source: Binary string: c:\develo~1\cdm2_2_4\pp\ftserui2\objfre_wnet_amd64\amd64\ftserui2.pdbH source: ftserui2.dll
Source: Binary string: c:\Development\cdm2_2_4\d2xxdll\x64\Release\FTD2XX64.pdb source: ftd2xx64.dll
Source: Binary string: c:\Development\cdm2_2_4\d2xxdll\Release\FTD2XX.pdb source: ftd2xx.dll
Source: Binary string: DpInst.pdbH source: CP210xVCPInstaller_64_Bit.exe
Source: Binary string: c:\develo~1\cdm2_2_4\pp\ftserui2\objfre_wnet_x86\i386\ftserui2.pdb source: ftserui2.dll
Source: Binary string: c:\dev\development\fixedfunction\cp210x\drivers\serialenumerationfilter\windows_xp_s2k3_vista_7\objchk_wxp_x86\i386\silabenm.pdb source: silabenm.sys
Source: Binary string: c:\develo~1\cdm2_2_4\coinst\ftcserco\objfre_wnet_amd64\amd64\ftcserco.pdbH source: ftcserco.dll
Source: Binary string: c:\dev\development\fixedfunction\cp210x\drivers\vcp\windows_2k_xp_s2k3_vista_7\objfre_wxp_x86\i386\silabser.pdb source: silabser.sys
Source: Binary string: c:\Development\cdm2_2_4\FTLang\x64\Release\FTLang.pdb source: ftlang.dll
Source: Binary string: c:\Development\cdm2_2_4\FTBUSUI\Release\FTBUSUI.pdb source: ftbusui.dll
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: USB-DRIVERS-ALL-11-14-13.exeStatic PE information: section name: _winzip_
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2959683385.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\y
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2404586996.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\y}
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000002.3312245226.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\y;
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2680263428.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\X
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2820894632.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\y
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2680263428.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2404586996.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2680263428.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}z
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2123323620.0000000001239000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2959621441.0000000001282000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATAr
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2123323620.0000000001239000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\WbR
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2123323620.0000000001239000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2680263428.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}oy}
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2680263428.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}y
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2959683385.0000000001219000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}:
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2404586996.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}y;
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2680263428.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2820894632.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}oy
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2123323620.0000000001239000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}E
Source: USB-DRIVERS-ALL-11-14-13.exe, 00000000.00000003.2404586996.000000000122B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: RUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftcserco.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftserui2.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftdibus.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftlang.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/WM-USB-WinXP-01A.pdf
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: QUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/FTClean.exe
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: FUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftd2xx.h
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: (GUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIPORT.CAT
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTCOMMS.VXD
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: FUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/COMPORT.PDF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftserui2.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: QUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: V\LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIUN2K.INI
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftserui2.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERIAL.SYS
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: QUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftserui2.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/FTDIUNIN.exe
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: O$ (.sUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/WM-USB-Vista7-01B.pdf
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftbusui.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftd2xx64.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIPORT.INF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: KUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSENUM.VXD
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: OUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftd2xx.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: k^USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/USB_FTDI_Setup.exe
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIPORT.INF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: .LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERUI.DLL
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIPORT.CAT
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: RUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftserui2.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: DUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftlang.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: XUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/WM-USB-WinXP-01A.pdf
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERIAL.SYS
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: ?GUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIPORT.INF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: UUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/FTClean.exe
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftd2xx.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftlang.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: @USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftbusui.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIUNIN.EXE
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIUNIN.EXE
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/FTClean.exe
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftdibus.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: TUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/WM-USB-WinXP-01A.pdf
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftd2xx.lib
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftbusui.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: EUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftser2k.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: JUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTLang.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIUN2K.INI
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/USB_FTDI_Setup.exe
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftser2k.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIBUS.CAT
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: FGUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIUNIN.EXE
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: OUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftdibus.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: AUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftcserco.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftsermou.cat
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/WM-USB-Vista7-01B.pdf
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: Rk^USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: @\U[LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIUNIN.INI
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIUNIN.INI
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIBUS.INF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERUI.DLL
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: splCEUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: JUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIUNIN.INI
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: KUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/COMPORT.PDF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: JUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSENUM.SYS
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: QUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftbusui.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: OUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftd2xx.lib
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: @USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERMOU.INF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERMOU.VXD
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: PUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftbusui.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: OUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/WM-USB-Vista7-01B.pdf
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: FUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftdibus.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: FUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTCOMMS.VXD
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: VUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/FTDIUNIN.exe
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftser2k.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: REGUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIUN2K.INI
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/USB_FTDI_Setup.exe
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: AUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftd2xx64.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: 7LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIPORT.CAT
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: Q$ R7DUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftdibus.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftbusui.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: %LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftsermou.cat
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: RUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftd2xx64.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: rplCFUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: Q$ _\QUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftserui2.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: JUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSENUM.VXD
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: V$ _KUUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/FTDIUNIN.exe
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: MUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftcserco.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTLang.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: aLUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftserui2.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftdibus.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: PUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftser2k.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftcserco.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: OUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftlang.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: FUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIBUS.CAT
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftd2xx.lib
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: QUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftser2k.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: IOUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftd2xx.lib
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSENUM.VXD
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: xnC:USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win_Vista-Win_7-OS/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: FUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIBUS.INF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: KUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIBUS.INF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: ^KUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftdibus.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/COMPORT.PDF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: EFUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftserui2.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: bKUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSENUM.SYS
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: PUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftlang.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftserui2.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: hMHUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftd2xx.h
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: KUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERIAL.SYS
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: KUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftser2k.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERMOU.INF
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERMOU.VXD
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftsermou.cat
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: splC@USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: PUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftdibus.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftser2k.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: splCJUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/utilities/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: QUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftdibus.sys
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/PK
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: PUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftlang.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: Q4KUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTDIBUS.CAT
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: \KUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTCOMMS.VXD
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: @USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: j$LUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERMOU.VXD
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/ftd2xx.h
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftcserco.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: AUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftd2xx.lib
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: 8CPUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/amd64/ftd2xx.lib
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: QUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftcserco.dll
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: USBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSENUM.SYS
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: b2Y2@XKUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/FTSERUI.DLL
Source: USB-DRIVERS-ALL-11-14-13.exeBinary or memory string: MUSBLinkOld-RemoteLinkII-CommLinkIII_IV-Win98_Win_2000-Win_XP-OS/i386/ftd2xx.dll
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
1
DLL Side-Loading
1
DLL Side-Loading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager1
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
USB-DRIVERS-ALL-11-14-13.exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://nsis.sf.net/NSIS_Error0%URL Reputationsafe
http://nsis.sf.net/NSIS_ErrorError0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.winzip.comUSB-DRIVERS-ALL-11-14-13.exefalse
    unknown
    http://nsis.sf.net/NSIS_ErrorUSB_FTDI_Setup.exefalse
    • URL Reputation: safe
    unknown
    http://nsis.sf.net/NSIS_ErrorErrorUSB_FTDI_Setup.exefalse
    • URL Reputation: safe
    unknown
    No contacted IP infos
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1546388
    Start date and time:2024-10-31 20:35:51 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 4m 5s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:4
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:USB-DRIVERS-ALL-11-14-13.exe
    Detection:CLEAN
    Classification:clean1.winEXE@1/0@0/0
    Cookbook Comments:
    • Found application associated with file extension: .exe
    • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
    • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
    • Report size getting too big, too many NtOpenKeyEx calls found.
    • Report size getting too big, too many NtProtectVirtualMemory calls found.
    • Report size getting too big, too many NtQueryValueKey calls found.
    • VT rate limit hit for: USB-DRIVERS-ALL-11-14-13.exe
    No simulations
    No context
    No context
    No context
    No context
    No context
    No created / dropped files found
    File type:PE32 executable (GUI) Intel 80386, for MS Windows
    Entropy (8bit):7.996502296182282
    TrID:
    • Win32 Executable (generic) a (10002005/4) 99.73%
    • Winzip Win32 self-extracting archive (generic) (23002/1) 0.23%
    • Generic Win/DOS Executable (2004/3) 0.02%
    • DOS Executable Generic (2002/1) 0.02%
    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
    File name:USB-DRIVERS-ALL-11-14-13.exe
    File size:7'715'840 bytes
    MD5:0cc5d1c6eb22a1c08ff1bf65c7802f32
    SHA1:98b2ce2711c43b184ffc2146eec2f01c1bb5ab6e
    SHA256:be3b6f84d3749adf2742a516efe65dc53425b744ff052486a39ede4503ab0591
    SHA512:09259d9462bb6ba2c62f1e59eee265fc597b5ba208213ba22c8e665cc02f9e07594425c4f1cb4444eb21de83bb7c79a6a82f622eab17c07fd9c1ac33059d4d51
    SSDEEP:196608:lP8p+MBB0EJChMHt5sTgC6xpg0nzCPFCwSVQiwkX:ljcJg2t5sTgh/nzgF0X
    TLSH:A4763345B2A6D838E1F31978D51D8A36C13D3E85C22E854776E83E6EEDE5EC8E2153C0
    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........O..]O..]O..] .h]Q..] .]]A..]O..]...]F.P]B..] .i]-..] .X]N..] .Y]N..]O.T]M..] .^]N..]RichO..]........PE..L......M...........
    Icon Hash:9bdbd9594d6c3c25
    Entrypoint:0x406791
    Entrypoint Section:.text
    Digitally signed:false
    Imagebase:0x400000
    Subsystem:windows gui
    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
    Time Stamp:0x4DDD1DBF [Wed May 25 15:18:23 2011 UTC]
    TLS Callbacks:
    CLR (.Net) Version:
    OS Version Major:5
    OS Version Minor:0
    File Version Major:5
    File Version Minor:0
    Subsystem Version Major:5
    Subsystem Version Minor:0
    Import Hash:221235b0ee3289d2e55bdedf1a6a37fb
    Instruction
    call 00007FEF08D0583Eh
    jmp 00007FEF08D02F0Eh
    sub eax, 000003A4h
    je 00007FEF08D030A4h
    sub eax, 04h
    je 00007FEF08D03099h
    sub eax, 0Dh
    je 00007FEF08D0308Eh
    dec eax
    je 00007FEF08D03085h
    xor eax, eax
    ret
    mov eax, 00000404h
    ret
    mov eax, 00000412h
    ret
    mov eax, 00000804h
    ret
    mov eax, 00000411h
    ret
    mov edi, edi
    push esi
    push edi
    mov esi, eax
    push 00000101h
    xor edi, edi
    lea eax, dword ptr [esi+1Ch]
    push edi
    push eax
    call 00007FEF08CFDA5Bh
    xor eax, eax
    movzx ecx, ax
    mov eax, ecx
    mov dword ptr [esi+04h], edi
    mov dword ptr [esi+08h], edi
    mov dword ptr [esi+0Ch], edi
    shl ecx, 10h
    or eax, ecx
    lea edi, dword ptr [esi+10h]
    stosd
    stosd
    stosd
    mov ecx, 004111A8h
    add esp, 0Ch
    lea eax, dword ptr [esi+1Ch]
    sub ecx, esi
    mov edi, 00000101h
    mov dl, byte ptr [ecx+eax]
    mov byte ptr [eax], dl
    inc eax
    dec edi
    jne 00007FEF08D03079h
    lea eax, dword ptr [esi+0000011Dh]
    mov esi, 00000100h
    mov dl, byte ptr [eax+ecx]
    mov byte ptr [eax], dl
    inc eax
    dec esi
    jne 00007FEF08D03079h
    pop edi
    pop esi
    ret
    mov edi, edi
    push ebp
    mov ebp, esp
    sub esp, 0000051Ch
    mov eax, dword ptr [00411198h]
    xor eax, ebp
    mov dword ptr [ebp-04h], eax
    push ebx
    push edi
    lea eax, dword ptr [ebp-00000518h]
    push eax
    push dword ptr [esi+04h]
    call dword ptr [0040E1B0h]
    mov edi, 00000100h
    Programming Language:
    • [C++] VS2010 build 30319
    • [ASM] VS2010 build 30319
    • [IMP] VS2008 SP1 build 30729
    • [ C ] VS2010 build 30319
    • [EXP] VS2010 build 30319
    • [RES] VS2010 build 30319
    • [LNK] VS2010 build 30319
    NameVirtual AddressVirtual Size Is in Section
    IMAGE_DIRECTORY_ENTRY_EXPORT0x10df00x32.rdata
    IMAGE_DIRECTORY_ENTRY_IMPORT0xffa40x8c.rdata
    IMAGE_DIRECTORY_ENTRY_RESOURCE0x170000x9388.rsrc
    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
    IMAGE_DIRECTORY_ENTRY_BASERELOC0x210000xe24.reloc
    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xfc880x40.rdata
    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IAT0xe0000x2a8.rdata
    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
    .text0x10000xcbda0xcc007e248f4a8e5eab0ca12629c7b026614fFalse0.5962009803921569data6.533725088543905IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    .rdata0xe0000x2e220x3000de645b3c2207370a7b6cbedbcba5aa3cFalse0.3528645833333333data4.992677573673642IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .data0x110000x55200x10009ba853384315d02b3cde90ad781ab8b2False0.232421875Windows boot log, header size 0x1, 0x70003 valid bytes; entry size 0xff01ff00, 0x1000000 seconds, GUID 0x000100030007000f001f003f007f00ff, severity 0xff07ff03, version 4280286991, event 0xff7fff3f2.4512964588590886IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
    .rsrc0x170000x93880x94009bb154d5acf618b6d15052c798ded0eaFalse0.31484902871621623data4.909352181946803IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .reloc0x210000x147e0x1600593f7d3711abfe06a360cb4a289a9e1cFalse0.5525568181818182data5.163964514910316IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
    _winzip_0x230000x7410000x740200f5cfafacc99bc80208002582d54aaf4eunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
    NameRVASizeTypeLanguageCountryZLIB Complexity
    RT_ICON0x199a80x668Device independent bitmap graphic, 48 x 96 x 4, image size 0EnglishUnited States0.3195121951219512
    RT_ICON0x1a0100x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 0EnglishUnited States0.3803763440860215
    RT_ICON0x1a2f80x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.6385135135135135
    RT_ICON0x1a4200xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0EnglishUnited States0.3288912579957356
    RT_ICON0x1b2c80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0EnglishUnited States0.3953068592057762
    RT_ICON0x1bb700x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.4913294797687861
    RT_ICON0x1c0d80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishUnited States0.34024896265560167
    RT_ICON0x1e6800x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.3918855534709193
    RT_ICON0x1f7280x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.4308510638297872
    RT_DIALOG0x174500x27edataEnglishUnited States0.5188087774294671
    RT_DIALOG0x201f00x192dataEnglishUnited States0.5920398009950248
    RT_STRING0x176d00x2fcMatlab v4 mat-file (little endian) h, numeric, rows 0, columns 0EnglishUnited States0.3717277486910995
    RT_STRING0x179d00x168dataEnglishUnited States0.5694444444444444
    RT_STRING0x17b380x8dedataEnglishUnited States0.3762114537444934
    RT_STRING0x184180x6ecdataEnglishUnited States0.33860045146726864
    RT_STRING0x18b080x946MIPSEB-LE MIPS-II ECOFF executable not stripped - version 0.101EnglishUnited States0.3074978938500421
    RT_STRING0x194500x4e2dataEnglishUnited States0.4096
    RT_STRING0x199380x6edataEnglishUnited States0.6727272727272727
    RT_GROUP_ICON0x1fb900x84dataEnglishUnited States0.6363636363636364
    RT_MANIFEST0x1fc180x5d4XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.4262734584450402
    DLLImport
    SHELL32.dllShellExecuteW, SHGetPathFromIDListA, SHBrowseForFolderA, SHGetMalloc, FindExecutableW
    USER32.dllGetSysColor, GetClientRect, SetRect, EndPaint, LoadCursorA, CharUpperBuffA, GetLastActivePopup, ShowWindow, PostMessageA, SendMessageA, EnableWindow, SetWindowTextA, SetForegroundWindow, SetActiveWindow, GetKeyState, MessageBoxW, GetParent, SetDlgItemTextA, SendDlgItemMessageA, GetDlgItem, BeginPaint, UpdateWindow, LoadStringA, MessageBoxA, GetWindowLongA, SetWindowLongA, wsprintfA, SetTimer, KillTimer, DialogBoxParamA, GetDlgItemTextA, EndDialog, GetWindowRect, GetSystemMetrics, SetWindowPos, PeekMessageA, TranslateMessage, DispatchMessageA, SetCursor, CharNextA, SetWindowWord, GetWindowWord, DefWindowProcA, RegisterClassA, InvalidateRect
    KERNEL32.dllGetConsoleCP, SetFilePointer, Sleep, HeapFree, EnterCriticalSection, LeaveCriticalSection, LCMapStringW, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, HeapCreate, DeleteCriticalSection, GetFileType, InitializeCriticalSectionAndSpinCount, SetHandleCount, GetEnvironmentStringsW, WideCharToMultiByte, FreeEnvironmentStringsW, GetStdHandle, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetStringTypeW, GetProcAddress, GetLastError, GetCurrentThreadId, SetLastError, GetModuleHandleW, TlsFree, DecodePointer, TlsSetValue, lstrcatA, FindClose, FindFirstFileA, GetCurrentDirectoryA, GetConsoleMode, CreateDirectoryA, SetFileTime, LocalFileTimeToFileTime, DosDateTimeToFileTime, LocalAlloc, GetDriveTypeA, lstrcpyA, _lclose, GlobalLock, GlobalAlloc, lstrlenA, GlobalFree, GlobalUnlock, GlobalHandle, GetEnvironmentVariableA, LocalFree, _llseek, _lread, _lopen, CloseHandle, WriteFile, CreateFileA, ExitProcess, GetModuleHandleA, _lcreat, GetVolumeInformationA, MultiByteToWideChar, CreateProcessW, lstrlenW, GetWindowsDirectoryA, lstrcmpiA, GlobalMemoryStatus, FlushFileBuffers, GetVersionExA, GetModuleFileNameA, GetSystemTime, _lwrite, GetModuleFileNameW, SetErrorMode, LoadLibraryW, HeapAlloc, HeapReAlloc, WriteConsoleW, SetStdHandle, HeapSize, CreateFileW, SetCurrentDirectoryA, GetVersion, RtlUnwind, GetCommandLineA, HeapSetInformation, GetStartupInfoW, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, EncodePointer, TlsAlloc, TlsGetValue
    GDI32.dllSetTextColor, SetTextAlign, GetBkColor, GetTextExtentPoint32A, ExtTextOutA, CreateDCA, GetDeviceCaps, CreateFontIndirectA, DeleteDC, SelectObject, DeleteObject, SetBkColor
    ADVAPI32.dllRegQueryValueW
    COMCTL32.dll
    Language of compilation systemCountry where language is spokenMap
    EnglishUnited States
    No network behavior found

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:15:36:41
    Start date:31/10/2024
    Path:C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\Desktop\USB-DRIVERS-ALL-11-14-13.exe"
    Imagebase:0x8c0000
    File size:7'715'840 bytes
    MD5 hash:0CC5D1C6EB22A1C08FF1BF65C7802F32
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    No disassembly