File name:

svd3.exe

Full analysis: https://app.any.run/tasks/01211397-8f09-45e8-be5c-18c0aa76c4c3
Verdict: Malicious activity
Analysis date: February 18, 2024, 15:32:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1E4CA550DFD1630376AB5FC8F48761CE

SHA1:

07B9131C01D939BF3C87B63E972F29AF3988F8E4

SHA256:

64DFE0993237666144CDB1A2C32649DB640E4E7E37DA831E37209C61B6D5ACAD

SSDEEP:

98304:EUJtekPcllBui6GLjx4BV07ERTni2yUxVsUv+lm+DDV9QSp16tc6v8Z8Uspit2bk:saTs0xjKdjexx85r

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • svd3.exe (PID: 1776)
      • GLBF32A.tmp (PID: 2964)
    • Registers / Runs the DLL via REGSVR32.EXE

      • GLBF32A.tmp (PID: 2964)
      • regsvr32.exe (PID: 864)
    • Steals credentials from Web Browsers

      • GLBF32A.tmp (PID: 2964)
      • SBUpdate.exe (PID: 2644)
    • Actions looks like stealing of personal data

      • GLBF32A.tmp (PID: 2964)
      • SBUpdate.exe (PID: 2644)
    • Creates a writable file in the system directory

      • GLBF32A.tmp (PID: 2964)
  • SUSPICIOUS

    • Reads the Internet Settings

      • GLBF32A.tmp (PID: 2964)
      • Converter.exe (PID: 4000)
      • SBUpdate.exe (PID: 2644)
    • Reads security settings of Internet Explorer

      • GLBF32A.tmp (PID: 2964)
      • Converter.exe (PID: 4000)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 1040)
      • regsvr32.exe (PID: 864)
      • regsvr32.exe (PID: 120)
      • GLJF369.tmp (PID: 2648)
      • GLJF369.tmp (PID: 2232)
    • Starts application with an unusual extension

      • svd3.exe (PID: 1776)
      • GLBF32A.tmp (PID: 2964)
    • Executable content was dropped or overwritten

      • svd3.exe (PID: 1776)
      • regsvr32.exe (PID: 864)
      • GLBF32A.tmp (PID: 2964)
    • Application launched itself

      • regsvr32.exe (PID: 864)
    • Creates a software uninstall entry

      • GLBF32A.tmp (PID: 2964)
    • Searches for installed software

      • GLBF32A.tmp (PID: 2964)
    • Reads the BIOS version

      • Converter.exe (PID: 4000)
    • Detected use of alternative data streams (AltDS)

      • Converter.exe (PID: 4000)
    • Changes the title of the Internet Explorer window

      • GLBF32A.tmp (PID: 2964)
    • Changes the Home page of Internet Explorer

      • GLBF32A.tmp (PID: 2964)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3864)
      • svd3.exe (PID: 1776)
      • TbHelper2.exe (PID: 2124)
      • GLJF369.tmp (PID: 2648)
      • GLJF369.tmp (PID: 2232)
      • Converter.exe (PID: 4000)
      • SBUpdate.exe (PID: 2644)
      • GLBF32A.tmp (PID: 2964)
    • Creates files in the program directory

      • GLBF32A.tmp (PID: 2964)
      • Converter.exe (PID: 4000)
    • Creates files or folders in the user directory

      • regsvr32.exe (PID: 864)
      • Converter.exe (PID: 4000)
      • GLBF32A.tmp (PID: 2964)
    • Drops the executable file immediately after the start

      • regsvr32.exe (PID: 864)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3864)
      • Converter.exe (PID: 4000)
      • SBUpdate.exe (PID: 2644)
      • GLBF32A.tmp (PID: 2964)
    • Create files in a temporary directory

      • svd3.exe (PID: 1776)
      • Converter.exe (PID: 4000)
      • GLBF32A.tmp (PID: 2964)
    • Reads the machine GUID from the registry

      • Converter.exe (PID: 4000)
      • SBUpdate.exe (PID: 2644)
      • GLBF32A.tmp (PID: 2964)
    • Checks proxy server information

      • Converter.exe (PID: 4000)
      • SBUpdate.exe (PID: 2644)
    • Manual execution by a user

      • msedge.exe (PID: 2772)
    • Application launched itself

      • msedge.exe (PID: 3308)
      • msedge.exe (PID: 2772)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (91.7)
.exe | Win64 Executable (generic) (5.3)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)
.exe | Generic Win/DOS Executable (0.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1999:04:08 20:24:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 512
InitializedDataSize: 6192128
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.0.1.0
ProductVersionNumber: 3.0.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: SPEEDbit Ltd.
FileDescription: SPEEDbit Video Downloader
FileVersion: 3.0.1
LegalCopyright: (c) 2008-2010
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
30
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start svd3.exe glbf32a.tmp regsvr32.exe no specs regsvr32.exe regsvr32.exe no specs tbhelper2.exe no specs gljf369.tmp no specs gljf369.tmp no specs converter.exe sbupdate.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs svd3.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120regsvr32 /s "C:\Program Files\SPEEDbit Video Downloader\Toolbar\TbCommonUtils.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
664"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1632 --field-trial-handle=1348,i,13650936701873154012,11041917004900968566,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
864"C:\Windows\System32\regsvr32.exe" /s "C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll"C:\Windows\System32\regsvr32.exe
GLBF32A.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1040"C:\Windows\System32\regsvr32.exe" /s "C:\Program Files\SPEEDbit Video Downloader\Toolbar\grabber.dll"C:\Windows\System32\regsvr32.exeGLBF32A.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1636"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1460 --field-trial-handle=1348,i,13650936701873154012,11041917004900968566,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1776"C:\Users\admin\AppData\Local\Temp\svd3.exe" C:\Users\admin\AppData\Local\Temp\svd3.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\svd3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
1892"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1512 --field-trial-handle=1400,i,14091723454230080401,7558278538881757821,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2088"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=1540 --field-trial-handle=1348,i,13650936701873154012,11041917004900968566,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2124"C:\Program Files\SPEEDbit Video Downloader\Toolbar\TbHelper2.exe" -RegServerC:\Program Files\SPEEDbit Video Downloader\Toolbar\TbHelper2.exeregsvr32.exe
User:
admin
Integrity Level:
HIGH
Description:
Toolbar Helper Module
Exit code:
0
Version:
4.2.0.75
Modules
Images
c:\program files\speedbit video downloader\toolbar\tbhelper2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2232"C:\Users\admin\AppData\Local\Temp\GLJF369.tmp" C:\Program Files\SearchPredict\SearchPredict.dllC:\Users\admin\AppData\Local\Temp\GLJF369.tmpGLBF32A.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\gljf369.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
Total events
9 148
Read events
8 688
Write events
422
Delete events
38

Modification events

(PID) Process:(2964) GLBF32A.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:GRRemove
Value:
(PID) Process:(2964) GLBF32A.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:Enable Browser Extensions
Value:
YES
(PID) Process:(2964) GLBF32A.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\AniGIF.ocx
Value:
1
(PID) Process:(2964) GLBF32A.tmpKey:HKEY_CURRENT_USER\Software\SpeedBit\Video Converter
Operation:writeName:EXELOCATION
Value:
C:\Program Files\SPEEDbit Video Downloader\Converter.exe
(PID) Process:(2964) GLBF32A.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\SpeedBit\Video Converter
Operation:writeName:EXELOCATION
Value:
C:\Program Files\SPEEDbit Video Downloader\Converter.exe
(PID) Process:(2964) GLBF32A.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\SpeedBit\Video Converter
Operation:writeName:FFUseConverter
Value:
1
(PID) Process:(2964) GLBF32A.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\SpeedBit\Video Converter
Operation:writeName:Install
Value:
C:\Program Files\SPEEDbit Video Downloader\
(PID) Process:(2964) GLBF32A.tmpKey:HKEY_CURRENT_USER\Software\SpeedBit\SearchPredict
Operation:writeName:Count
Value:
01000000000
(PID) Process:(2964) GLBF32A.tmpKey:HKEY_CURRENT_USER\Software\SpeedBit\SearchPredict
Operation:writeName:Aff
Value:
svd_NONE
(PID) Process:(2964) GLBF32A.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions
Operation:writeName:searchpredict@speedbit.com
Value:
C:\Program Files\SearchPredict\PRFireFox
Executable files
83
Suspicious files
37
Text files
335
Unknown types
29

Dropped files

PID
Process
Filename
Type
2964GLBF32A.tmpC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:3B2E23D259394C701050486E642D14FA
SHA256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1
2964GLBF32A.tmpC:\Users\admin\AppData\Local\Temp\GLCF359.tmpexecutable
MD5:8C97D8BB1470C6498E47B12C5A03CE39
SHA256:A87F19F9FEE475D2B2E82ACFB4589BE6D816B613064CD06826E1D4C147BEB50A
1776svd3.exeC:\Users\admin\AppData\Local\Temp\GLBF32A.tmpexecutable
MD5:748FE5E21D134C63046221A2A04837EE
SHA256:A6B104CD2AE6B54F0734CC2D9DEB0F63633BBB9798C99388AF08EB77F65458A9
2964GLBF32A.tmpC:\Users\admin\AppData\Local\Temp\GLJF369.tmpexecutable
MD5:6F608D264503796BEBD7CD66B687BE92
SHA256:49833D2820AFB1D7409DFBD916480F2CDF5787D2E2D94166725BEB9064922D5D
2964GLBF32A.tmpC:\Users\admin\AppData\Local\Temp\GLKF55E.tmpexecutable
MD5:D22557EBC659DCD0C89266E4A42A041E
SHA256:0045A481E8F141E10927ABE09B3D1608E3C123B402F8C89A7BE319E088F4A0F5
2964GLBF32A.tmpC:\Users\admin\AppData\Local\Temp\~GLH0002.TMPhtml
MD5:766291A9D7E573C4415E499DF68CD6F3
SHA256:58918D7EF4CB5E14C03749CA0E5C4EAD656FA5E705C9B5A3BACD3A8400ABAA51
2964GLBF32A.tmpC:\Users\admin\AppData\Local\Temp\~GLH0001.TMPexecutable
MD5:626891C542239F7AEBC156F9B244E433
SHA256:06C30D0CC9C035AF22B69BE795C0A1BAB200E832CC556B41853FD18FBDEDCDAC
2964GLBF32A.tmpC:\Users\admin\AppData\Local\Temp\GLFFF24.tmpexecutable
MD5:3B2E23D259394C701050486E642D14FA
SHA256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1
2964GLBF32A.tmpC:\Users\admin\AppData\Local\Temp\SVCINST\SpeedBitVideoDownloader.cabcompressed
MD5:E82945B4E4D15C0F5E46C79582804F0F
SHA256:8C8A34B2579233C7A14B8A34E1EABCBB1917984B900CC17B1EA4FD4701E2D811
2964GLBF32A.tmpC:\Users\admin\AppData\Local\Temp\SVCINST\Grabber.dllexecutable
MD5:175C8B9CBEFC7F2FC1CEB420D3B80BDE
SHA256:7ABC5C8809FE79896F2C8123FD3942853504221707114CF5CA9FD92F86895785
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
18
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4000
Converter.exe
GET
108.156.61.182:80
http://download.speedbit.com/ffmpeg.zip
unknown
unknown
4000
Converter.exe
GET
108.156.61.182:80
http://download.speedbit.com/ffmpeg.zip
unknown
unknown
4000
Converter.exe
GET
108.156.61.182:80
http://download.speedbit.com/ffmpeg.zip
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4000
Converter.exe
108.156.61.182:80
download.speedbit.com
AMAZON-02
US
unknown
4000
Converter.exe
173.239.4.56:80
online.speedbit.com
WEBAIR-INTERNET
US
unknown
1636
msedge.exe
173.239.4.63:80
www.speedbit.com
WEBAIR-INTERNET
US
unknown
2772
msedge.exe
239.255.255.250:1900
unknown
1636
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1636
msedge.exe
131.253.33.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1636
msedge.exe
92.123.104.66:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
download.speedbit.com
  • 108.156.61.182
  • 108.156.61.86
  • 108.156.61.201
  • 108.156.61.173
whitelisted
online.speedbit.com
  • 173.239.4.56
unknown
www.speedbit.com
  • 173.239.4.63
malicious
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 131.253.33.239
  • 13.107.22.239
whitelisted
www.bing.com
  • 92.123.104.66
  • 92.123.104.62
  • 92.123.104.59
  • 92.123.104.53
  • 92.123.104.58
  • 92.123.104.60
  • 92.123.104.5
  • 92.123.104.64
  • 92.123.104.67
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 23.50.131.27
  • 23.50.131.24
whitelisted

Threats

No threats detected
Process
Message
regsvr32.exe
[SbTracer::UpdateAllParameters]
regsvr32.exe
[SbTracer::ReadConfiguration] ___Warning - No Trace Level
regsvr32.exe
[SbTracer::ReadConfiguration] ___Warning - No Trace Destination
regsvr32.exe
[SbTracer::ReadConfiguration] ___Warning - No Trace Backup
regsvr32.exe
[SbTracer::ReadConfiguration] ___Warning - No Trace Time Limit
regsvr32.exe
[SbTracer::ReadConfiguration] ___Warning - No Trace Time Stamp
regsvr32.exe
[SbTracer::ReadConfiguration] ___Warning - No Trace Max Size
regsvr32.exe
[SbTracer::ReadConfiguration] Done
regsvr32.exe
[SbTracer::FormatFilePath] ___Warning - No Log folder: C:\Windows\System32\
regsvr32.exe
[SbTracer::FormatFilePath] Log Path: C:\Windows\System32\Grabber.log