File name:

microsoft office 2007 service pack 2.exe.zip

Full analysis: https://app.any.run/tasks/ef5e4e53-8367-4bb3-a02c-b458d935c4f0
Verdict: Malicious activity
Analysis date: March 02, 2024, 16:48:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

EBE8B633D231BBFEE9543D744A2AB59D

SHA1:

9D3395D94C6BBBA52ABF0E6AFCBF4CA312597C21

SHA256:

4842C6E6A522207C69870B6BE3B04F3FD00BB5225C8A4C9E921991E477908ED5

SSDEEP:

3072:VzvXGeqnbr/OPvmT4ZLTLetuRcmr9rujM3fK2eiPr4ch15A/G:VrHmOLpCQamhruQF/Zz5A/G

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • csc.exe (PID: 2100)
      • csc.exe (PID: 1340)
      • csc.exe (PID: 2320)
      • WinRAR.exe (PID: 3668)
      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
    • Starts Visual C# compiler

      • sdiagnhost.exe (PID: 2432)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
    • Reads settings of System Certificates

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • msdt.exe (PID: 3068)
      • northstar.exe (PID: 3496)
    • The process creates files with name similar to system file names

      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
    • Checks Windows Trust Settings

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • northstar.exe (PID: 3496)
    • Reads security settings of Internet Explorer

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • northstar.exe (PID: 3496)
    • Executable content was dropped or overwritten

      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • csc.exe (PID: 2100)
      • csc.exe (PID: 1340)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
      • csc.exe (PID: 2320)
      • microsoft office 2007 service pack 2.exe (PID: 2636)
    • Probably uses Microsoft diagnostics tool to execute malicious payload

      • pcwrun.exe (PID: 1560)
    • Process drops legitimate windows executable

      • msdt.exe (PID: 3068)
    • Reads the Internet Settings

      • sdiagnhost.exe (PID: 2432)
    • Uses .NET C# to load dll

      • sdiagnhost.exe (PID: 2432)
  • INFO

    • Manual execution by a user

      • microsoft office 2007 service pack 2.exe (PID: 3772)
      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2692)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • pcwrun.exe (PID: 1560)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
    • Reads the computer name

      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • northstar.exe (PID: 4060)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • northstar.exe (PID: 2756)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
      • northstar.exe (PID: 3496)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3668)
    • Reads the machine GUID from the registry

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • csc.exe (PID: 2100)
      • cvtres.exe (PID: 1368)
      • csc.exe (PID: 1340)
      • cvtres.exe (PID: 2260)
      • csc.exe (PID: 2320)
      • cvtres.exe (PID: 2888)
      • northstar.exe (PID: 3496)
    • Checks supported languages

      • northstar.exe (PID: 4060)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • northstar.exe (PID: 2756)
      • csc.exe (PID: 2100)
      • cvtres.exe (PID: 2260)
      • cvtres.exe (PID: 1368)
      • csc.exe (PID: 1340)
      • csc.exe (PID: 2320)
      • cvtres.exe (PID: 2888)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
      • northstar.exe (PID: 3496)
      • microsoft office 2007 service pack 2.exe (PID: 2636)
    • Reads the software policy settings

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • msdt.exe (PID: 3068)
      • northstar.exe (PID: 3496)
    • Reads Environment values

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • northstar.exe (PID: 3496)
    • Create files in a temporary directory

      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • pcwrun.exe (PID: 1560)
      • msdt.exe (PID: 3068)
      • sdiagnhost.exe (PID: 2432)
      • csc.exe (PID: 2100)
      • cvtres.exe (PID: 1368)
      • csc.exe (PID: 1340)
      • cvtres.exe (PID: 2260)
      • csc.exe (PID: 2320)
      • cvtres.exe (PID: 2888)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
      • microsoft office 2007 service pack 2.exe (PID: 2636)
    • Drops the executable file immediately after the start

      • msdt.exe (PID: 3068)
    • Reads security settings of Internet Explorer

      • msdt.exe (PID: 3068)
      • sdiagnhost.exe (PID: 2432)
    • Creates files or folders in the user directory

      • msdt.exe (PID: 3068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 819
ZipBitFlag: 0x0001
ZipCompression: Unknown (99)
ZipModifyDate: 2012:12:27 15:15:52
ZipCRC: 0x00000000
ZipCompressedSize: 139448
ZipUncompressedSize: 178920
ZipFileName: microsoft office 2007 service pack 2.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
18
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe microsoft office 2007 service pack 2.exe no specs microsoft office 2007 service pack 2.exe northstar.exe no specs microsoft office 2007 service pack 2.exe no specs microsoft office 2007 service pack 2.exe northstar.exe no specs pcwrun.exe no specs msdt.exe no specs sdiagnhost.exe no specs csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs microsoft office 2007 service pack 2.exe northstar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1340"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\s9c6impk.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
sdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1368C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES6ADB.tmp" "c:\Users\admin\AppData\Local\Temp\CSC6ADA.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
1560C:\Windows\system32\pcwrun.exe "C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe"C:\Windows\System32\pcwrun.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Program Compatibility Troubleshooter Invoker
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\pcwrun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2100"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\feg-snok.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
sdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2260C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES6B49.tmp" "c:\Users\admin\AppData\Local\Temp\CSC6B48.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
2320"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\fs52dff7.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
sdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2420"C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe" C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
microsoft-office-2007-service-pack-2
Exit code:
0
Version:
2.2.49.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
2432C:\Windows\System32\sdiagnhost.exe -EmbeddingC:\Windows\System32\sdiagnhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Scripted Diagnostics Native Host
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sdiagnhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2636"C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe" C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
microsoft-office-2007-service-pack-2
Exit code:
0
Version:
2.2.49.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
2692"C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe" C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
microsoft-office-2007-service-pack-2
Exit code:
3221226540
Version:
2.2.49.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
c:\windows\system32\ntdll.dll
Total events
27 459
Read events
27 375
Write events
81
Delete events
3

Modification events

(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
12
Suspicious files
16
Text files
23
Unknown types
1

Dropped files

PID
Process
Filename
Type
2100csc.exeC:\Users\admin\AppData\Local\Temp\CSC6ADA.tmpbinary
MD5:968481526B91FC84D841C554EEECD92A
SHA256:EB7B541751E54F9982A0B0E5025C69118E285C5B17423637C27E805120E74863
2100csc.exeC:\Users\admin\AppData\Local\Temp\feg-snok.pdbbinary
MD5:F4CA55103DABAD74E11B110B81A8A1E6
SHA256:79C2AE2F6E5CD0248930736CD9B5CA57EFC2D9B76FAD13BE5E9E954799D97085
2432sdiagnhost.exeC:\Users\admin\AppData\Local\Temp\feg-snok.cmdlinetext
MD5:95FF96BB32F3F98229E10F792ED15338
SHA256:599A1E07859570928B4CCC06705CDD7579FBD002EAA6B64D417BA7AEA5644E8D
3068msdt.exeC:\Users\admin\AppData\Local\Temp\SDIAG_3fdce756-dbb7-4a6b-ad41-819a3c5f11ac\en-US\DiagPackage.dll.muiexecutable
MD5:C31BD28AB34E75BC65A5458AC8D37539
SHA256:5FB9E280013D58043C5689478F9DCFAD3212F4681534627EB33998DDD6F63308
2432sdiagnhost.exeC:\Users\admin\AppData\Local\Temp\feg-snok.0.cstext
MD5:B0DC59B099CA7C12FB8AD72D3C50C82C
SHA256:E75EAAA3D7908FB05000C0A957048D20091A0D2575E87D091D11CDB3A5B562E5
3068msdt.exeC:\Users\admin\AppData\Local\Temp\SDIAG_3fdce756-dbb7-4a6b-ad41-819a3c5f11ac\result\results.xslxml
MD5:310E1DA2344BA6CA96666FB639840EA9
SHA256:67401342192BABC27E62D4C1E0940409CC3F2BD28F77399E71D245EAE8D3F63C
3068msdt.exeC:\Users\admin\AppData\Local\Temp\SDIAG_3fdce756-dbb7-4a6b-ad41-819a3c5f11ac\TS_ProgramCompatibilityWizard.ps1text
MD5:46E22C2582B54BE56D80D7A79FEC9BB5
SHA256:459AF2960B08E848573D45A7350223657ADB2115F24A3C37E69FFE61DEA647F9
3068msdt.exeC:\Users\admin\AppData\Local\Temp\SDIAG_3fdce756-dbb7-4a6b-ad41-819a3c5f11ac\en-US\CL_LocalizationData.psd1text
MD5:863DC7FD9D5E14BB639EAAF596D64416
SHA256:97EB6F256A278FF10B200FA6E248B7A89BA956D9F533D138302C7F3721A95D8E
1560pcwrun.exeC:\Users\admin\AppData\Local\Temp\PCW6712.xmlxml
MD5:80681B26E76818EC8BB3F99F3C1B1D97
SHA256:B32857E34DD8099890EC37E3D642C8738D942DEBA5FB85C0EDCB09FADCB7F0C2
3068msdt.exeC:\Users\admin\AppData\Local\Temp\SDIAG_3fdce756-dbb7-4a6b-ad41-819a3c5f11ac\RS_ProgramCompatibilityWizard.ps1text
MD5:367FE5F4C6DB87E1600F46687E5AAC54
SHA256:177625AC9B07BBFFCBBB47101C2D1121F47B03B42226861BFD7974B9CEBC0C98
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
api.downloadmr.com
unknown

Threats

No threats detected
Process
Message
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144