File name:

synology-assistant-7.0.4-50051.exe

Full analysis: https://app.any.run/tasks/1ada8be9-f2f8-431f-9871-982cffd30190
Verdict: Malicious activity
Analysis date: July 19, 2024, 18:04:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

52E3A08DB193757A35011A942AC8C6C8

SHA1:

027E80A4A334035DE2DE84E65170B6DAB60FE510

SHA256:

0858F796EB7FCEBE6B7108B247B28A47519E9A103CA57A66C6AD45161FE00249

SSDEEP:

98304:7pqVROEewkySv3Jdvt6/jJCJ1vNZWvVIxjXWFvnbjqTcnRmWUWdUYuZagWO65eQn:qq/WFDMEncnRWwOMhxp2u/zW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
      • devcon.exe (PID: 3364)
      • drvinst.exe (PID: 3860)
      • drvinst.exe (PID: 2724)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 3860)
      • drvinst.exe (PID: 2724)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
    • Executable content was dropped or overwritten

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
      • devcon.exe (PID: 3364)
      • drvinst.exe (PID: 3860)
      • drvinst.exe (PID: 2724)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
    • Process drops legitimate windows executable

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
    • The process creates files with name similar to system file names

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
    • Drops a system driver (possible attempt to evade defenses)

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
      • devcon.exe (PID: 3364)
      • drvinst.exe (PID: 3860)
      • drvinst.exe (PID: 2724)
    • Creates a software uninstall entry

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
    • Reads security settings of Internet Explorer

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
      • devcon.exe (PID: 3364)
    • Reads the Internet Settings

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
    • Starts CMD.EXE for commands execution

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
    • Executing commands from a ".bat" file

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
    • Checks Windows Trust Settings

      • devcon.exe (PID: 3364)
      • drvinst.exe (PID: 3860)
      • drvinst.exe (PID: 2724)
    • Reads settings of System Certificates

      • devcon.exe (PID: 3364)
      • rundll32.exe (PID: 2036)
    • Adds/modifies Windows certificates

      • devcon.exe (PID: 3364)
    • Executes as Windows Service

      • UsbClientService.exe (PID: 2408)
      • VSSVC.exe (PID: 2524)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3860)
      • drvinst.exe (PID: 2724)
  • INFO

    • Reads Environment values

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
    • Reads the computer name

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
      • UsbClientService.exe (PID: 2852)
      • UsbClientService.exe (PID: 1952)
      • devcon.exe (PID: 2580)
      • UsbClientService.exe (PID: 2408)
      • devcon.exe (PID: 3364)
      • drvinst.exe (PID: 3860)
      • DSAssistant.exe (PID: 3324)
      • drvinst.exe (PID: 2724)
    • Checks supported languages

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
      • UsbClientService.exe (PID: 2852)
      • devcon.exe (PID: 2580)
      • UsbClientService.exe (PID: 1952)
      • devcon.exe (PID: 3364)
      • drvinst.exe (PID: 3860)
      • UsbClientService.exe (PID: 2408)
      • DSAssistant.exe (PID: 3324)
      • drvinst.exe (PID: 2724)
    • Create files in a temporary directory

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
      • devcon.exe (PID: 3364)
    • Creates files in the program directory

      • synology-assistant-7.0.4-50051.exe (PID: 3372)
      • UsbClientService.exe (PID: 2408)
    • Reads the machine GUID from the registry

      • devcon.exe (PID: 3364)
      • drvinst.exe (PID: 2724)
      • drvinst.exe (PID: 3860)
      • DSAssistant.exe (PID: 3324)
    • Reads the software policy settings

      • devcon.exe (PID: 3364)
      • drvinst.exe (PID: 3860)
      • rundll32.exe (PID: 2036)
      • drvinst.exe (PID: 2724)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 2036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
15
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start synology-assistant-7.0.4-50051.exe cmd.exe no specs cmd.exe no specs devcon.exe no specs usbclientservice.exe no specs usbclientservice.exe no specs usbclientservice.exe no specs devcon.exe drvinst.exe rundll32.exe no specs vssvc.exe no specs dsassistant.exe drvinst.exe synology-assistant-7.0.4-50051.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1952UsbClientService.exe -startC:\Program Files\Synology\Assistant\UsbClientService.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\synology\assistant\usbclientservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
2036rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{5b5ff258-363d-1286-6c62-0e446c62a004} Global\{259cad78-942f-3eff-a1c1-e2260613dd01} C:\Windows\System32\DriverStore\Temp\{7aec7285-626c-440e-b75b-2823d98a3d1a}\bus.inf C:\Windows\System32\DriverStore\Temp\{7aec7285-626c-440e-b75b-2823d98a3d1a}\synodriverx86.catC:\Windows\System32\rundll32.exedrvinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2408"C:\Program Files\Synology\Assistant\UsbClientService.exe"C:\Program Files\Synology\Assistant\UsbClientService.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files\synology\assistant\usbclientservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
2524C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2580..\devcon.exe update bus.inf root\busenumC:\Program Files\Synology\Assistant\driver\version_release\x86\devcon.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
2
Version:
6.1.7600.16385 (win7_wdk.100208-1538)
Modules
Images
c:\program files\synology\assistant\driver\version_release\x86\devcon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2724DrvInst.exe "2" "211" "ROOT\USB\0000" "C:\Windows\INF\oem2.inf" "bus.inf:Standard:Virutal_USB:1.0.2.4:root\busenum" "674a88703" "0000030C" "000005F4" "000005F8"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2852UsbClientService.exe -setupC:\Program Files\Synology\Assistant\UsbClientService.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\synology\assistant\usbclientservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
2900C:\Windows\system32\cmd.exe /c ""C:\Program Files\Synology\Assistant\install-service.bat" "C:\Windows\System32\cmd.exesynology-assistant-7.0.4-50051.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2948C:\Windows\system32\cmd.exe /c ""C:\Program Files\Synology\Assistant\driver\version_release\x86\win7\install-driver.bat" "C:\Windows\System32\cmd.exesynology-assistant-7.0.4-50051.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3324"C:\Program Files\Synology\Assistant\DSAssistant.exe"C:\Program Files\Synology\Assistant\DSAssistant.exe
synology-assistant-7.0.4-50051.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\program files\synology\assistant\dsassistant.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
20 253
Read events
20 025
Write events
226
Delete events
2

Modification events

(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_CURRENT_USER\Software\Synology\DSAssistant
Operation:writeName:Installer Language
Value:
1033
(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant
Operation:writeName:DisplayName
Value:
Synology Assistant (remove only)
(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant
Operation:writeName:UninstallString
Value:
C:\Program Files\Synology\Assistant\Uninstall.exe
(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Synology\Assistant\DSAssistant.exe,0
(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant
Operation:writeName:InstalledVersion
Value:
50051
(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant
Operation:writeName:DisplayVersion
Value:
7.0.4-50051
(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant
Operation:writeName:Publisher
Value:
Synology
(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3372) synology-assistant-7.0.4-50051.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
43
Suspicious files
42
Text files
36
Unknown types
2

Dropped files

PID
Process
Filename
Type
3372synology-assistant-7.0.4-50051.exeC:\Users\admin\AppData\Local\Temp\nsnE4A0.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
3372synology-assistant-7.0.4-50051.exeC:\Program Files\Synology\Assistant\concrt140.dllexecutable
MD5:BB7293ADD679A5688FCDD03F44DE4B90
SHA256:F3093CB216BF8ECC8D869E46D8CDA3AACA28A326CB865CCBEF329E1B13ABC834
3372synology-assistant-7.0.4-50051.exeC:\Program Files\Synology\Assistant\DSAssistant.exeexecutable
MD5:0F0D0AD7422CEA1A8AB66B2ED0213630
SHA256:74C6F7420EA70EBCFE208605441D5B87ED1C940A8258D6936C6045C9CFF7C196
3372synology-assistant-7.0.4-50051.exeC:\Users\admin\AppData\Local\Temp\nsnE4A0.tmp\UserInfo.dllexecutable
MD5:2F69AFA9D17A5245EC9B5BB03D56F63C
SHA256:E54989D2B83E7282D0BEC56B098635146AAB5D5A283F1F89486816851EF885A0
3372synology-assistant-7.0.4-50051.exeC:\Program Files\Synology\Assistant\DSAssistantStart.battext
MD5:2DCDEF6F4816BC89380022A043941DB1
SHA256:4AFF687B7B613DC7A4619CB0F03872BCE685353AA3D41B774D51F2B786370061
3372synology-assistant-7.0.4-50051.exeC:\Program Files\Synology\Assistant\Qt5Gui.dllexecutable
MD5:D268011D393AB81C3BE2F7A20435BCB0
SHA256:EB1111379DFDF84CF7F027837F54C4854EE4B1AC45A1716D8CF6D5A2D38A46A6
3372synology-assistant-7.0.4-50051.exeC:\Program Files\Synology\Assistant\LICENSEtext
MD5:35AD1BA57C692DB0A3842EF181CA5593
SHA256:B734A5EB74465F09DC6DE8E3355B9E181FC2949D12DD3654708F3B1DA5554794
3372synology-assistant-7.0.4-50051.exeC:\Users\admin\AppData\Local\Temp\nsnE4A0.tmp\nsDialogs.dllexecutable
MD5:6C3F8C94D0727894D706940A8A980543
SHA256:56B96ADD1978B1ABBA286F7F8982B0EFBE007D4A48B3DED6A4D408E01D753FE2
3372synology-assistant-7.0.4-50051.exeC:\Program Files\Synology\Assistant\UsbClientService.exeexecutable
MD5:51581A26573D6FC3F9626C1B5F2CC508
SHA256:F5CA6CCC3880204C25F7D83426927B13A6B0E787E1B8EF3DD3EAC51B9B617483
3372synology-assistant-7.0.4-50051.exeC:\Program Files\Synology\Assistant\Qt5Widgets.dllexecutable
MD5:6BCC8769D857F72E20C607B2B172D404
SHA256:3866964F40840E6FA323494880578EA1D4D803B128FC12CDC5271F9072FF4696
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
15
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
whitelisted
1372
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1372
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1060
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbe613066ac7852b
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1372
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
2564
svchost.exe
239.255.255.250:3702
whitelisted
4
System
192.168.100.255:138
whitelisted
1372
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1372
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1372
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
dns.msftncsi.com
  • 131.107.255.255
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
Process
Message
DSAssistant.exe
src\main.cpp:172 Version: 7.0.4-50051
DSAssistant.exe
..\libcommon\SynoLocale.cpp:64 qPrintable(qstrLocaleLower)=[en_us ]
DSAssistant.exe
..\libcommon\SynoLocale.cpp:80 qPrintable(qstrLocaleLower)=[en_us]
DSAssistant.exe
..\libcommon\SynoLocale.cpp:161 qPrintable(qstrLangFileName)=[:/enu.qm]
DSAssistant.exe
..\libcommon\SynoLocale.cpp:138 qPrintable(qstrDef)=[enu ]
DSAssistant.exe
..\libcommon\SynoLocale.cpp:64 qPrintable(qstrLocaleLower)=[en_us ]
DSAssistant.exe
..\libcommon\SynoLocale.cpp:80 qPrintable(qstrLocaleLower)=[en_us]
DSAssistant.exe
..\libcommon\SynoLocale.cpp:161 qPrintable(qstrLangFileName)=[:/enu.qm]
DSAssistant.exe
..\libcommon\SynoLocale.cpp:138 qPrintable(qstrDef)=[enu ]
DSAssistant.exe
src\WizardAddPrinter\CMultiFuncPtr.cpp:385 open PtrConf-file failed.