Windows Analysis Report
Install_PCIE_Win11_11021_09012024_12202024.exe

Overview

General Information

Sample name: Install_PCIE_Win11_11021_09012024_12202024.exe
Analysis ID: 1592108
MD5: 67a86d9326bbf651787fd729af3481b9
SHA1: ad7126506c2ce1f7c9a951251bd0c2f2a0cf15dc
SHA256: 6131fef95c3a619abf550f032fb6deb533352ac384efe3bcb791a6b1524680c3
Infos:

Detection

Score: 3
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

Creates driver files
Creates or modifies windows services
Drops PE files
Drops certificate files (DER)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\FAQ\8168C_manual_install.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\FAQ\Change_installer_language.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\FAQ\Driver_Installer_Rollback.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\FAQ\Use_installer_to_auto_remove_driver.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setupctrl.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\PCIE_WIN11_RTL81xx_INSTALLPKG_RELEASE_NOTE .txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\WinPE\readme.txt Jump to behavior
Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static PE information: certificate valid
Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static PE information: DYNAMIC_BASE, NX_COMPAT
Source: Binary string: C:\CodeBases\isdev\redist\Language Independent\i386\ISP\ISSetup.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, ISS47E7.tmp.2.dr, ISSetup.dll.0.dr
Source: Binary string: C:\CodeBases\isdev\redist\Language Independent\i386\ISP\setup.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000000.1730004404.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000001.00000002.2333036871.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000002.00000000.1733542113.00000000003D7000.00000002.00000001.01000000.00000005.sdmp, setup.exe, 00000002.00000002.2325235818.00000000003D7000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt26cx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\redist\Language Independent\i386\ISP\setup.pdb' source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000000.1730004404.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000001.00000002.2333036871.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000002.00000000.1733542113.00000000003D7000.00000002.00000001.01000000.00000005.sdmp, setup.exe, 00000002.00000002.2325235818.00000000003D7000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: C:\git\RTInstaller\SRC\x64\Release\RTInstaller64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp, RTInstaller64.dat.0.dr
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt68dcx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt25cx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt25dcx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt68cx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\Src\Runtime\InstallScript\ISBEW64\x64\Release\ISBEW64.pdb source: ISBEW64.exe, 00000004.00000002.2189576348.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000004.00000000.1892030847.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000005.00000002.1896270237.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000005.00000000.1893180225.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000006.00000000.1894022941.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000006.00000002.1900693249.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000007.00000000.1895045847.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000007.00000002.1901222863.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000008.00000000.1896861246.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000008.00000002.1901838333.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000009.00000002.2178438264.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000009.00000000.1900759187.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: C:\git\ndis6_driver\sysw10x64\Release\x64\rt640x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728523434.0000000002FE0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\git\RTInstaller\SRC\Release\RTInstaller32.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000000.1730004404.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000001.00000002.2333036871.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000002.00000000.1733542113.00000000003D7000.00000002.00000001.01000000.00000005.sdmp, setup.exe, 00000002.00000002.2325235818.00000000003D7000.00000002.00000001.01000000.00000005.sdmp String found in binary or memory: http://=0x%04x.iniTahomaFontNamePropertiesFontSize%ld123.tmptemp/
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, dotDC8E.tmp.2.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, dotDC8E.tmp.2.dr, ISSetup.dll.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, dotDC8E.tmp.2.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, dotDC8E.tmp.2.dr, ISSetup.dll.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000003.1732798520.00000000054FC000.00000004.00000020.00020000.00000000.sdmp, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, ISSetup.dll.0.dr String found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, dotDC8E.tmp.2.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, dotDC8E.tmp.2.dr, ISSetup.dll.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, dotDC8E.tmp.2.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: dotDC8E.tmp.2.dr, ISSetup.dll.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: dotDC8E.tmp.2.dr String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, ISSetup.dll.0.dr String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0=
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000003.1732798520.00000000054FC000.00000004.00000020.00020000.00000000.sdmp, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, ISSetup.dll.0.dr String found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
Source: data1.hdr.0.dr String found in binary or memory: http://deviis4.installshield.com/NetNirvana/
Source: setup.exe, 00000002.00000003.2202296245.0000000007447000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://deviis4.installshield.com/NetNirvana//
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.000000000374C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://deviis4.installshield.com/NetNirvana/ISc(T
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, dotDC8E.tmp.2.dr, ISSetup.dll.0.dr String found in binary or memory: http://ocsp.digicert.com0
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, dotDC8E.tmp.2.dr, ISSetup.dll.0.dr String found in binary or memory: http://ocsp.digicert.com0A
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, dotDC8E.tmp.2.dr String found in binary or memory: http://ocsp.digicert.com0C
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, dotDC8E.tmp.2.dr String found in binary or memory: http://ocsp.digicert.com0X
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000003.1732798520.00000000054FC000.00000004.00000020.00020000.00000000.sdmp, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, ISSetup.dll.0.dr String found in binary or memory: http://ocsp.sectigo.com0
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000002.2333961609.00000000054CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2090697842.000000000A190000.00000004.00000800.00020000.00000000.sdmp, setup.exe, 00000002.00000003.1810757586.00000000077C0000.00000004.00000800.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2090539414.000000000A190000.00000004.00000800.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2181248208.0000000009CBE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2182511573.00000000077CB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2182652731.00000000077CC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2202296245.0000000007441000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2328872908.00000000077CF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2090823271.000000000A190000.00000004.00000800.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2180791422.0000000009C9F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2321499400.00000000077CD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2195491187.00000000077CD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2332341035.0000000009CBE000.00000004.00000020.00020000.00000000.sdmp, setup.ini.1.dr String found in binary or memory: http://www.Realtek.com
Source: setup.exe, 00000002.00000003.2323543493.0000000005368000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2326277681.000000000536B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.Realtek.comF
Source: setup.exe, 00000002.00000003.2181248208.0000000009CBE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2180791422.0000000009C9F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2332341035.0000000009CBE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.Realtek.comOMPANY
Source: setup.exe, 00000001.00000002.2333961609.00000000054CA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.Realtek.comn
Source: data1.hdr.0.dr String found in binary or memory: http://www.Realtek.comrCtC
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, dotDC8E.tmp.2.dr, ISSetup.dll.0.dr String found in binary or memory: http://www.digicert.com/CPS0
Source: dotDC8E.tmp.2.dr String found in binary or memory: http://www.flexerasoftware.com0
Source: setup.exe, 00000001.00000002.2333961609.00000000054CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000001.00000002.2333036871.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000002.00000003.2090697842.000000000A190000.00000004.00000800.00020000.00000000.sdmp, setup.exe, 00000002.00000000.1733542113.00000000003D7000.00000002.00000001.01000000.00000005.sdmp, setup.exe, 00000002.00000003.1810757586.00000000077C0000.00000004.00000800.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2325235818.00000000003D7000.00000002.00000001.01000000.00000005.sdmp, setup.exe, 00000002.00000003.2090539414.000000000A190000.00000004.00000800.00020000.00000000.sdmp, setup.exe, 00000002.00000003.1797285476.0000000005433000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.1796335699.0000000005422000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2090823271.000000000A190000.00000004.00000800.00020000.00000000.sdmp, setup.exe, 00000002.00000003.1796367585.000000000542E000.00000004.00000020.00020000.00000000.sdmp, setup.ini.1.dr, ISS47E7.tmp.2.dr, ISSetup.dll.0.dr String found in binary or memory: http://www.installshield.com/isetup/ProErrorCentral.asp?ErrorCode=%d
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp, contactInfo.html35.0.dr, contactInfo.html30.0.dr, contactInfo.html6.0.dr, contactInfo.html41.0.dr, contactInfo.html4.0.dr, contactInfo.html33.0.dr, contactInfo.html15.0.dr, contactInfo.html29.0.dr String found in binary or memory: http://www.realtek.com.tw
Source: troubleshooting.html18.0.dr String found in binary or memory: http://www.realtek.com.tw/downloads
Source: troubleshooting.html2.0.dr String found in binary or memory: http://www.realtek.com/downloads
Source: Install_PCIE_Win11_11021_09012024_12202024.exe String found in binary or memory: http://www.winzip.com
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000003.1732798520.00000000054FC000.00000004.00000020.00020000.00000000.sdmp, ISS47E7.tmp.2.dr, RTInstaller64.dat.0.dr, ISSetup.dll.0.dr String found in binary or memory: https://sectigo.com/CPS0
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt68dcx21x64.cat Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt25dcx21x64.cat Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt26cx21x64.cat Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt25cx21x64.sys Jump to behavior
Source: ISSetup.dll.0.dr Static PE information: Resource name: PUBLICKEY type: b.out overlay separate pure segmented executable V2.3 186 286 286 386 Large Text Large Data Huge Objects Enabled
Source: ISSetup.dll.2.dr Static PE information: Resource name: PUBLICKEY type: b.out overlay separate pure segmented executable V2.3 186 286 286 386 Large Text Large Data Huge Objects Enabled
Source: ISS47E7.tmp.2.dr Static PE information: Resource name: PUBLICKEY type: b.out overlay separate pure segmented executable V2.3 186 286 286 386 Large Text Large Data Huge Objects Enabled
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesetup.exef# vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamert25cx21x64.sys vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamert25dcx21x64.sys vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamert26cx21x64.sys vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamert68cx21x64.sys vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamert68dcx21x64.sys vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamert640x64.sys vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameRTInstaller.exe8 vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728523434.0000000002FE0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamert640x64.sys vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameiKernel.dll vs Install_PCIE_Win11_11021_09012024_12202024.exe
Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: rt25cx21x64.sys.0.dr Binary string: RtReadStringDataFromRegistry( adapter, REG_GUID, guid, (ULONG)guidSize)\Device\RealTekCard
Source: classification engine Classification label: clean3.winEXE@19/768@0/0
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\InstallShield Installation Information\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Mutant created: \Sessions\1\BaseNamedObjects\8833FFB6-5B0C-4764-81AA-06DFEED9A476
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2076:120:WilError_03
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1 Jump to behavior
Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe File read: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.ini Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File read: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe "C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe"
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Process created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe .\setup.exe
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe -no_selfdeleter -IS_temp -media_path:"C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\" -tempdisk1folder:"C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\" -IS_OriginalLauncher:"C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe"
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{C04C0F50-C018-4044-812E-7216AB620FB4}
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{34C5F3D2-7D5E-49D8-A2B7-B71E30235B8F}
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{BF202879-2E98-422F-AD0A-33C0D0F4554B}
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{22A04FCC-7F78-4DC4-AC36-C09DFCD86B65}
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{2CBCD3A0-4ADD-4C9D-B827-03F32D6EAB61}
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{5E066103-5CBC-4D12-B1D7-79637AB91A64}
Source: unknown Process created: C:\Windows\System32\SrTasks.exe C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1
Source: C:\Windows\System32\SrTasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Process created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe .\setup.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe -no_selfdeleter -IS_temp -media_path:"C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\" -tempdisk1folder:"C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\" -IS_OriginalLauncher:"C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{C04C0F50-C018-4044-812E-7216AB620FB4} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{34C5F3D2-7D5E-49D8-A2B7-B71E30235B8F} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{BF202879-2E98-422F-AD0A-33C0D0F4554B} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{22A04FCC-7F78-4DC4-AC36-C09DFCD86B65} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{2CBCD3A0-4ADD-4C9D-B827-03F32D6EAB61} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{5E066103-5CBC-4D12-B1D7-79637AB91A64} Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: riched32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: srclient.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: spp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: vssapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: vsstrace.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: sxproxy.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: srclient.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: spp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: vssapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: vsstrace.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: spp.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srclient.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ktmw32.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: wer.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: bcd.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: dsrole.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: msxml3.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vss_ps.dll
Source: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File written: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\0x0402.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File opened: C:\Windows\SysWOW64\RICHED32.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static PE information: certificate valid
Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static file information: File size 5403520 > 1048576
Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static PE information: DYNAMIC_BASE, NX_COMPAT
Source: Binary string: C:\CodeBases\isdev\redist\Language Independent\i386\ISP\ISSetup.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, ISS47E7.tmp.2.dr, ISSetup.dll.0.dr
Source: Binary string: C:\CodeBases\isdev\redist\Language Independent\i386\ISP\setup.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000000.1730004404.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000001.00000002.2333036871.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000002.00000000.1733542113.00000000003D7000.00000002.00000001.01000000.00000005.sdmp, setup.exe, 00000002.00000002.2325235818.00000000003D7000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt26cx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\redist\Language Independent\i386\ISP\setup.pdb' source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000001.00000000.1730004404.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000001.00000002.2333036871.0000000000137000.00000002.00000001.01000000.00000004.sdmp, setup.exe, 00000002.00000000.1733542113.00000000003D7000.00000002.00000001.01000000.00000005.sdmp, setup.exe, 00000002.00000002.2325235818.00000000003D7000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: C:\git\RTInstaller\SRC\x64\Release\RTInstaller64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp, RTInstaller64.dat.0.dr
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt68dcx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt25cx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt25dcx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\Hau\Desktop\RtEthSample\x64\Release\rt68cx21x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\Src\Runtime\InstallScript\ISBEW64\x64\Release\ISBEW64.pdb source: ISBEW64.exe, 00000004.00000002.2189576348.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000004.00000000.1892030847.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000005.00000002.1896270237.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000005.00000000.1893180225.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000006.00000000.1894022941.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000006.00000002.1900693249.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000007.00000000.1895045847.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000007.00000002.1901222863.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000008.00000000.1896861246.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000008.00000002.1901838333.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000009.00000002.2178438264.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp, ISBEW64.exe, 00000009.00000000.1900759187.00007FF6DDADD000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: C:\git\ndis6_driver\sysw10x64\Release\x64\rt640x64.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.00000000032BF000.00000004.00001000.00020000.00000000.sdmp, Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728523434.0000000002FE0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\git\RTInstaller\SRC\Release\RTInstaller32.pdb source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1722471754.0000000003767000.00000004.00001000.00020000.00000000.sdmp
Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static PE information: real checksum: 0x5303fc should be: 0x53043c
Source: Install_PCIE_Win11_11021_09012024_12202024.exe Static PE information: section name: .sxdata
Source: ISSetup.dll.0.dr Static PE information: section name: .orpc
Source: ISSetup.dll.0.dr Static PE information: section name: .didat
Source: setup.exe.0.dr Static PE information: section name: .didat
Source: RTInstaller64.dat.0.dr Static PE information: section name: _RDATA
Source: setup.exe.1.dr Static PE information: section name: .didat
Source: ISSetup.dll.2.dr Static PE information: section name: .orpc
Source: ISSetup.dll.2.dr Static PE information: section name: .didat
Source: RTI56E2.tmp.2.dr Static PE information: section name: _RDATA
Source: ISBDCA0.tmp.2.dr Static PE information: section name: _RDATA
Source: isrDCB2.tmp.2.dr Static PE information: section name: .didat
Source: set4769.tmp.2.dr Static PE information: section name: .didat
Source: ISS47E7.tmp.2.dr Static PE information: section name: .orpc
Source: ISS47E7.tmp.2.dr Static PE information: section name: .didat
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\Realtek\NICDRV_8169\RTInstaller64.dat (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt25dcx21x64.sys Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt68dcx21x64.sys Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt25cx21x64.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt68cx21x64.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\isrt.dll (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\TOOL\RTInstaller64.dat Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\Realtek\NICDRV_8169\RTI56E2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\set4769.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\Realtek\NICDRV_8169\RTInstaller32.dat (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\dotDC8E.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBDCA0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\ISSetup.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\Realtek\NICDRV_8169\RTI56C2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\_isDD02.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe File created: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rtots640x64.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\_isres_0x0409.dll (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\ISSetup.dll Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\TOOL\RTInstaller32.dat Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\Realtek\NICDRV_8169\RTINSTALLER64.EXE (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt26cx21x64.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\ISBEW64.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\ISS47E7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\ISSetup.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\isrDCB2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\dotnetinstaller.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\FAQ\8168C_manual_install.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\FAQ\Change_installer_language.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\FAQ\Driver_Installer_Rollback.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\FAQ\Use_installer_to_auto_remove_driver.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setupctrl.txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\PCIE_WIN11_RTL81xx_INSTALLPKG_RELEASE_NOTE .txt Jump to behavior
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe File created: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\WinPE\readme.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Registry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore Jump to behavior
Source: C:\Windows\System32\SrTasks.exe Registry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Realtek\NICDRV_8169\RTInstaller64.dat (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt25dcx21x64.sys Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt25cx21x64.sys Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt68dcx21x64.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\ISSetup.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Realtek\NICDRV_8169\RTI56C2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\_isDD02.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt68cx21x64.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\isrt.dll (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rtots640x64.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\_isres_0x0409.dll (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\TOOL\RTInstaller64.dat Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Realtek\NICDRV_8169\RTI56E2.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\ISSetup.dll Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\TOOL\RTInstaller32.dat Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Realtek\NICDRV_8169\RTINSTALLER64.EXE (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Install_PCIE_Win11_11021_09012024_12202024.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\WIN11\64\rt26cx21x64.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Realtek\NICDRV_8169\RTInstaller32.dat (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\dotDC8E.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\ISS47E7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\ISSetup.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\isrDCB2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{0DBDB5AE-00FC-4318-AA06-EA7AE0ED6A30}\dotnetinstaller.exe (copy) Jump to dropped file
Source: C:\Windows\System32\SrTasks.exe TID: 5824 Thread sleep time: -300000s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe File Volume queried: C:\Windows FullSizeInformation Jump to behavior
Source: SrTasks.exe, 0000000F.00000003.2202457257.00000203EAE41000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \Device\HarddiskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
Source: setup.exe, 00000002.00000003.2178601740.0000000009AC1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2183940814.0000000009AD5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2181468376.0000000009AC6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2175987727.0000000009AC1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2195290779.00000000074D0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2197290394.00000000074D8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0_IsVirtualMachine
Source: setup.exe, 00000002.00000003.2198527187.00000000074A0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2182511573.00000000077CB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2182652731.00000000077CC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2328872908.00000000077CF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2321499400.00000000077CD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2195491187.00000000077CD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachinengID
Source: setup.exe, 00000002.00000003.2190074204.000000000785F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2187274427.0000000007834000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2184316421.00000000077EA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2192339640.0000000007863000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2182511573.00000000077CB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2186543897.0000000007815000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2182652731.00000000077CC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2188572959.0000000007858000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2186994561.0000000007825000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2185263800.0000000007803000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachine0nN
Source: setup.exe, 00000002.00000003.2198910396.00000000074BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2196574814.00000000074BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2195696242.00000000074B5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2203589633.00000000074BD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2199363952.00000000074BD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2195864730.00000000074BB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2201676998.00000000074BC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0_GetVirtualMachineType+v_}Z
Source: setup.exe, 00000002.00000003.2182511573.00000000077CB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2182652731.00000000077CC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2328872908.00000000077CF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2321499400.00000000077CD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2195491187.00000000077CD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachine4
Source: setup.exe, 00000002.00000003.2181248208.0000000009CBE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2182511573.00000000077CB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2182652731.00000000077CC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2328872908.00000000077CF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2180791422.0000000009C9F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2321499400.00000000077CD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2195491187.00000000077CD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2332341035.0000000009CBE000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: _IsVirtualMachine
Source: SrTasks.exe, 0000000F.00000003.2174910299.00000203EAE3D000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: diskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
Source: setup.exe, 00000002.00000003.2193132122.0000000007952000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2192493882.0000000007952000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2194484470.000000000796C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachine=%ld:
Source: setup.exe, 00000002.00000003.2180956326.0000000009AFE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2177868457.0000000009AFB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2198527187.00000000074A0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2175987727.0000000009AC1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachine
Source: setup.exe, 00000002.00000003.2193132122.0000000007952000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2192493882.0000000007952000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2194484470.000000000796C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachineA
Source: SrTasks.exe, 0000000F.00000003.2121913381.00000203EAE3E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \Device\HarddiskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:88
Source: SrTasks.exe, 0000000F.00000003.2179422122.00000203EAE3D000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \Device\HarddiskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:__
Source: SrTasks.exe, 0000000F.00000003.2111168182.00000203EAE52000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: diskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D://
Source: setup.exe, 00000002.00000003.2178601740.0000000009AC1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2183940814.0000000009AD5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2181468376.0000000009AC6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2175987727.0000000009AC1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0_GetVirtualMachineTypeW
Source: setup.exe, 00000002.00000003.2180956326.0000000009AFE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2177868457.0000000009AFB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2175987727.0000000009AC1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachine=%ld&
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe c:\users\user\appdata\local\temp\{08625531-5ac3-4609-8c24-4011ed314ee8}\setup.exe -no_selfdeleter -is_temp -media_path:"c:\users\user\appdata\local\temp\7zs4ca48cc1\" -tempdisk1folder:"c:\users\user\appdata\local\temp\{08625531-5ac3-4609-8c24-4011ed314ee8}\" -is_originallauncher:"c:\users\user\appdata\local\temp\7zs4ca48cc1\setup.exe"
Source: C:\Users\user\AppData\Local\Temp\7zS4CA48CC1\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{08625531-5AC3-4609-8C24-4011ED314EE8}\setup.exe c:\users\user\appdata\local\temp\{08625531-5ac3-4609-8c24-4011ed314ee8}\setup.exe -no_selfdeleter -is_temp -media_path:"c:\users\user\appdata\local\temp\7zs4ca48cc1\" -tempdisk1folder:"c:\users\user\appdata\local\temp\{08625531-5ac3-4609-8c24-4011ed314ee8}\" -is_originallauncher:"c:\users\user\appdata\local\temp\7zs4ca48cc1\setup.exe" Jump to behavior
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, ISS47E7.tmp.2.dr, ISSetup.dll.0.dr Binary or memory string: ?OPTYPE_PROGMAN_FIELDSWWW
Source: setup.exe, 00000002.00000003.2202296245.0000000007447000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2204058413.0000000007461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2203704675.0000000007458000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMANG
Source: Install_PCIE_Win11_11021_09012024_12202024.exe, 00000000.00000003.1728968016.0000000003060000.00000004.00001000.00020000.00000000.sdmp, ISS47E7.tmp.2.dr, ISSetup.dll.0.dr Binary or memory string: ISGlobalOpTypesTableISLOG_VERSION_INFOC:\CodeBases\isdev\Src\Shared\LogServices2\LogDB.cppOPTYPE_PROGMANISLOGDB_USER_PROPERTIES
Source: setup.exe, 00000002.00000003.2202296245.0000000007447000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2204058413.0000000007461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2203704675.0000000007458000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMAN
No contacted IP infos