General Info

File name

directx.exe

Full analysis
https://app.any.run/tasks/766094f7-2e09-41d2-816d-36ff104958f9
Verdict
Malicious activity
Analysis date
4/15/2019, 11:46:14
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive
MD5

880a353dc9ab4202f2cfbec1cb37181d

SHA1

0bafee10ed68194fb332d3b46f7d92c8ad962843

SHA256

6b5c9cec68c7f3c0ba98b8d0b335f1be8ea4cd37fb02b4c81ecc1a95ef6d9578

SSDEEP

6144:OWK8faaQMbjFtVNtHb7RGb/Mp7mgypysDVpU2drVxP:LaaQMXDFFfp7S5DbU2RP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes the autorun value in the registry
  • directx.exe (PID: 2088)
Application was dropped or rewritten from another process
  • dxwsetup.exe (PID: 2744)
Loads dropped or rewritten executable
  • dxwsetup.exe (PID: 2744)
Changes settings of System certificates
  • dxwsetup.exe (PID: 2744)
Executable content was dropped or overwritten
  • directx.exe (PID: 2088)
  • dxwsetup.exe (PID: 2744)
Adds / modifies Windows certificates
  • dxwsetup.exe (PID: 2744)
Creates files in the Windows directory
  • dxwsetup.exe (PID: 2744)
Removes files from Windows directory
  • dxwsetup.exe (PID: 2744)
Reads settings of System Certificates
  • dxwsetup.exe (PID: 2744)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2001:08:18 03:42:57+02:00
PEType:
PE32
LinkerVersion:
7
CodeSize:
34816
InitializedDataSize:
258048
UninitializedDataSize:
null
EntryPoint:
0x5a5e
OSVersion:
5.1
ImageVersion:
5.1
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
6.0.2600.0
ProductVersionNumber:
6.0.2600.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Microsoft Corporation
FileDescription:
DirectX 9.0 Web setup
FileVersion:
9.28.1886.0
InternalName:
DXWebSetup
LegalCopyright:
Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName:
dxwebsetup.exe
ProductName:
Microsoft® Windows® Operating System
ProductVersion:
9.28.1886.0
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
18-Aug-2001 01:42:57
Detected languages
English - United States
Debug artifacts
.pdb
CompanyName:
Microsoft Corporation
FileDescription:
DirectX 9.0 Web setup
FileVersion:
9.28.1886.0
InternalName:
DXWebSetup
LegalCopyright:
Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFilename:
dxwebsetup.exe
ProductName:
Microsoft® Windows® Operating System
ProductVersion:
9.28.1886.0
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000C8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
3
Time date stamp:
18-Aug-2001 01:42:57
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000861A 0x00008800 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.55102
.data 0x0000A000 0x00001BE4 0x00000400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.18428
.rsrc 0x0000C000 0x0003F000 0x0003EC00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.834
Resources
1

2

63

76

77

80

83

85

2001

2002

2003

2004

2005

2006

3000

3001

ADMQCMD

CABINET

EXTRACTOPT

FILESIZES

FINISHMSG

LICENSE

PACKINSTSPACE

POSTRUNPROGRAM

REBOOT

RUNPROGRAM

SHOWWINDOW

TITLE

UPROMPT

USRQCMD

Imports
    ADVAPI32.dll

    KERNEL32.dll

    GDI32.dll

    USER32.dll

    COMCTL32.dll

    VERSION.dll

Exports

    No exports.

Screenshots

Processes

Total processes
36
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

+
drop and start start directx.exe no specs directx.exe dxwsetup.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2504
CMD
"C:\Users\admin\AppData\Local\Temp\directx.exe"
Path
C:\Users\admin\AppData\Local\Temp\directx.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft Corporation
Description
DirectX 9.0 Web setup
Version
9.28.1886.0
Modules
Image
c:\users\admin\appdata\local\temp\directx.exe
c:\systemroot\system32\ntdll.dll

PID
2088
CMD
"C:\Users\admin\AppData\Local\Temp\directx.exe"
Path
C:\Users\admin\AppData\Local\Temp\directx.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
DirectX 9.0 Web setup
Version
9.28.1886.0
Modules
Image
c:\users\admin\appdata\local\temp\directx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advpack.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe

PID
2744
CMD
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
Path
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
Indicators
Parent process
directx.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
DirectX Setup
Version
4.9.0.0904
Modules
Image
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\ole32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advpack.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\spfileq.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\directx\websetup\dsetup.dll
c:\windows\system32\directx\websetup\dsetup32.dll
c:\windows\system32\ntkrnlpa.exe
c:\windows\system32\clbcatq.dll
c:\windows\system32\inseng.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\dxupdate.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\microsoft.net\framework\v2.0.50727\fusion.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll

Registry activity

Total events
64
Read events
32
Write events
32
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2088
directx.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
wextract_cleanup0
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
setupapi.app.log
4096
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
EnableFileTracing
0
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
EnableConsoleTracing
0
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
FileTracingMask
4294901760
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
ConsoleTracingMask
4294901760
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
MaxFileSize
1048576
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
FileDirectory
%windir%\tracing
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
EnableFileTracing
0
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
EnableConsoleTracing
0
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
FileTracingMask
4294901760
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
ConsoleTracingMask
4294901760
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
MaxFileSize
1048576
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
FileDirectory
%windir%\tracing
2744
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2744
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2744
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2744
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2744
dxwsetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
0F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B812000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
2744
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D03000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B810B000000010000000E00000074006800610077007400650000001D00000001000000100000005B3B67000EEB80022E42605B6B3B72401400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB57485053000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703030F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE2000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68

Files activity

Executable files
6
Suspicious files
68
Text files
729
Unknown types
1

Dropped files

PID
Process
Filename
Type
2088
directx.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup.dll
executable
MD5: 8dc08c0effffc3d08e8718260843d10c
SHA256: 9ad6f392a736ba7e137ac7a49bc454e1457c91372ffec8effd4e779716a1f07d
2744
dxwsetup.exe
C:\Windows\system32\directx\websetup\dsetup.dll
executable
MD5: 8dc08c0effffc3d08e8718260843d10c
SHA256: 9ad6f392a736ba7e137ac7a49bc454e1457c91372ffec8effd4e779716a1f07d
2744
dxwsetup.exe
C:\Windows\system32\directx\websetup\dsetup32.dll
executable
MD5: f6b14958d2a93750c3d4fad02ca739be
SHA256: 529c3e93c1a7cbb0225ab5f12c5bb0e91eb905ebf3db7fc00cbd96d8e66a6f0e
2088
directx.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup32.dll
executable
MD5: f6b14958d2a93750c3d4fad02ca739be
SHA256: 529c3e93c1a7cbb0225ab5f12c5bb0e91eb905ebf3db7fc00cbd96d8e66a6f0e
2088
directx.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
executable
MD5: a2772e5a8df5dc3487e8516321ed29da
SHA256: 8fac859dc73ab7a8c18f093c6a58accf3ee8f1b86a4bcfce4c9e8a1253d2828f
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxupdate.dll
executable
MD5: a2a0da126c1a2f8b615b363e862989a2
SHA256: 300abf15fc1b38373053b898ad9a57098fa5656f26325f45b3d644befa74d428
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Aug2009_d3dx10_42_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS11221B.tmp\Aug2009_d3dx10_42_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 24c2adfbd8a53252fa8c6b7b11335cfd
SHA256: 755146ab2368788b39cc5b5e793cd4c401d44487916b6d7c43b3323ecc91f35a
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_d3dx9_42_x86.cab
compressed
MD5: bea370e85329d63aed0e601bd1cce9cf
SHA256: 50428a21e1e1f647586c59b9b3825812355cae5ff99d9c95c346823289691025
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 2a639c1089b8fbc137ec0c43c9fedd26
SHA256: 528027d033b9438e9d2cd729e735c5473a6a2f1e7247cf6a549473700f609172
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS112027.tmp\Aug2009_d3dx9_42_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Aug2009_d3dx9_42_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: b826651d2247dc6ac368cdfcd563cb12
SHA256: 68ed2ff4e51b966906ce3cf9c325e54b9c7e17151760655be271ae41e94103bb
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 84ee6bc6aff17f52f4e751a63c9daadd
SHA256: 30b92d7d3336ebf2e847560e144ea411741b2c83a0a3520c0826dc60cfaff1b1
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_d3dx10_41_x86.cab
compressed
MD5: a5d35900348e30709999c6a554efa54d
SHA256: 9066290e428327ff54691b1c7bb398f405c43561d54b86d7069ded2a26d3f57e
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Mar2009_d3dx10_41_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS111DA7.tmp\Mar2009_d3dx10_41_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: fee76496bf11bdb9eda5748f3d43d4a7
SHA256: f761742acb90c2e76ab126134af7f4d7a4f7e6c140c95087ae5d790e6b469cd4
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 2857d8006a8b0d772acbbadabb0dbb44
SHA256: 8c47a3e7cc57305fa54c47010018cf7d0219cd6c5b08ea86c8e60cae8b6529c6
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_d3dx9_41_x86.cab
compressed
MD5: 0fdd6e4e5dfc5d913261355746402214
SHA256: 5146e15d4c65590704286bfcfbbcc31e98a6832f8a7cc3bfdcb1e7fa5a647bb1
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Mar2009_d3dx9_41_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS1119DE.tmp\Mar2009_d3dx9_41_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 58ad181301d3247bc2af87c922455ac2
SHA256: 3ad666f8ec1df8efc6481058b1676a09caf9158e093c47e645e78ad3e26f7648
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: d962107b7de7882e80f645e94983476e
SHA256: 3eff8ddce4a8366bf9bcf622ec4e1961cc4b2742b07a8e88cd0e7e69f59ec8b8
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_d3dx10_40_x86.cab
compressed
MD5: e629a763baf3299fd80b80ff0eb00322
SHA256: 0470da172786ae0252a71afb00367b7c7afa9e98fd41957dfb83b6d61d128385
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS11176D.tmp\Nov2008_d3dx10_40_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Nov2008_d3dx10_40_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: c73589069b1f07700bcff5aea66e5a0f
SHA256: 9ce12a5940f2e9ee54465b6dc029e0bcc13238c683995205831cb1677413cd8c
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: ceab1d5f17c145b4762f9b0b33a7fac5
SHA256: 741c2d347703219364cfae942b2367727e7d414580bed0f057a6bf1ec7a1fe2f
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_d3dx9_40_x86.cab
compressed
MD5: a61b2774fb986cd23a44b0681e619451
SHA256: ce8d54fedb855a0ca0ea7b3ee6e6b2e1dc5cd991232a4e59b9d28ad5a6439b34
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS111395.tmp\Nov2008_d3dx9_40_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Nov2008_d3dx9_40_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 54731927f798d41af1a27535f69caa72
SHA256: e939c74a1fbc77666a0d306f29578a55f04d747c2b0e494de9c8e55a6aa89782
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: ec96fa82c9824d99c6a9f97df28ae962
SHA256: aea001d19b7b5d78a7ff80f478ff65b135d17e505b5712958c4451653b4d804e
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2008_d3dx10_39_x86.cab
compressed
MD5: 5a31e6881ad56e76b0eb22925ac6b9d5
SHA256: ee8c4530a3f99c3c6a39af9da2a7b5d17b603c731a1bf6db50a6ff4b599b7da3
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS111181.tmp\Aug2008_d3dx10_39_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Aug2008_d3dx10_39_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 7ee745b25389ee92aeef074bc51da228
SHA256: 17cd023b94ad12d00ed6cc2a94fcd913cffa597c154b7bb795ca3f42a4e7beb0
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2008_d3dx9_39_x86.cab
compressed
MD5: 2cddda31dbbcf137ddab9d2ec3b985a9
SHA256: 5db5dbab3516b4384f88eefcf9f9a3efc0185f96f9970809415b5869ef4bfaa3
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 52c45e26c77cb51282e518ffa4cfad86
SHA256: 6822dc8325b8a832f02df14273723e5f70af9ef19ff9b2f1fc4bc2cf646d5246
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS110E16.tmp\Aug2008_d3dx9_39_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Aug2008_d3dx9_39_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 0f10cfd5dae4f20e7cfd75786f583fd8
SHA256: e89229d25d8bfb0e7c1f68bfa5761bcc03b62f96723400b5ce65f7346683e488
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_d3dx10_38_x86.cab
compressed
MD5: 5e856008534714aa28d9831966ee3885
SHA256: 0c340ce49145d3486d3e3cf462a12a64cd164e7055ba552be01e8a209d5f9b0f
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: bfbda2848a0b57bc0ff7420d0565a66c
SHA256: e78e9eda0532bc30b2844b489cb9cf8dbb9c31d9fff79f8f3da1163d29ae0b4d
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS110C03.tmp\Jun2008_d3dx10_38_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Jun2008_d3dx10_38_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 705ec0140edc9b650381dcaeb7b40b67
SHA256: 69b9437bd55da3dfd24ff135fc9ceb3dd74c3f6e2c90364a4cc468576bc08abd
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_d3dx9_38_x86.cab
compressed
MD5: 2fa7b2deb22a59dfef971055688bbf09
SHA256: 487aa2267f8b1c0d41e0616f80d74da1595024411aa9ae8ebe8cbe3968ab4411
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 7a465f6cf669db694f998c85ef44a087
SHA256: 474c200344e03cdd7e6e42daa51a9e4a4e4eb95b54d468b05124e83e8cde09c1
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Jun2008_d3dx9_38_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS110898.tmp\Jun2008_d3dx9_38_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: ff339f31dc30a5f8028de5098e5eeec2
SHA256: 2f548d0d520e90903c9aaee427c78608f357a0ddcfd2d070e954a6410b08966d
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 1b1f0cdc45b1984e22b05e3de10fb563
SHA256: af706f7680ebfa7368c5f0c2b160e24ae78da1cfd65f32611da2bf3ddfd7d845
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_d3dx10_37_x86.cab
compressed
MD5: 581ad29fe85131801cb8edeb3c7208e9
SHA256: fc572c89db7da22c9c825e857287f7e29f49c25e53880b42a93fec64a81f6b29
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Mar2008_d3dx10_37_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS110694.tmp\Mar2008_d3dx10_37_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 40eb82b8990ed2919f7029f22e392d3c
SHA256: fe5855c36a20b53ffcae89f62760e81b26001bdec9632852def8177daf03bcea
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 86f742bda6c9fe46314c74252ba0a652
SHA256: c8eb2735812ecfe534a7ee75e91fa1f5f4ceb3b303c3ace408458693d8c427ac
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_d3dx9_37_x86.cab
compressed
MD5: 923d8e1c74ca96104a0d6383b854b703
SHA256: ac2ae155a503f149b4b4c396518c117ff0c3cfbf7c7c15a4b17301f0a4d61870
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS110329.tmp\Mar2008_d3dx9_37_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Mar2008_d3dx9_37_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: f89cc0705dc77e40ee1b6a770524a2ba
SHA256: c142726ee300ca8c0422a1e1e17e2dff080bdd8930bc02e70aa966fe2e2d0c3d
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 11e0360b60035a12c8966868db8baedd
SHA256: b1696b7eb827c0dfcfc5d1cf9ed8611b45a321e06cca88c1583995910dda1320
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2007_d3dx10_36_x86.cab
compressed
MD5: 0b1e9e97980d8521abd16be113b337dc
SHA256: bb0a026fee644fe5b60e313800cf19a0c83caa83b3b55e6a7dbd0397e4030489
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Nov2007_d3dx10_36_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS1100B8.tmp\Nov2007_d3dx10_36_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2007_d3dx9_36_x86.cab
compressed
MD5: 0ff5d771ef1f0e332ee69970dde1924f
SHA256: 4420aab0dde802e1122846ca9262949f8b019a66b73be921dcfbaa4e93158aab
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: fe66ec2223d72924e13e79d2296d66bd
SHA256: bfb771981537d5f8fd437b4bb35bbbdf52bab1abbe90284da99e1ee5ce7e6738
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 7f4d9c524216ececab070fd86e493481
SHA256: e0597e191b6dca6f6ee4c7f18338d10c8e996971d768b7c375193aba602f4e7f
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10FCC1.tmp\Nov2007_d3dx9_36_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Nov2007_d3dx9_36_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: ec0ca876e9206c5255bdf2946b097cce
SHA256: 881c7d3142852dbc2ef4ec2a478fac78456c274405adfc6f4c63d16856efd508
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 396f9c6da29a780dba01ed021a9e45e8
SHA256: f4defa80b97b440ab2983b7e06e16b918aa20eb16aaa3281a27b93d1ff69886f
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2007_d3dx10_35_x86.cab
compressed
MD5: 42cb75225876d842bf24246dfc19e652
SHA256: a66d617cd830e045df3fab6bce92293e79f521587e4e14fd76b6266aed35a75e
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10FABD.tmp\Aug2007_d3dx10_35_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Aug2007_d3dx10_35_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: cc0d1f8c4a2819db6de91d78b422684a
SHA256: 309c4bbece34991ebf1addbc950002dd0bb07b4ea477e1539923e18638671cef
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 4863082d7e293e925ee6948525de9343
SHA256: d6f5b3a138bc0526e40ca52000bfca5f978da884114e6c6683ca074f402d5796
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2007_d3dx9_35_x86.cab
compressed
MD5: 5289cee14b9055683b773d0f97157cd9
SHA256: ca84242679f5e6c75bfbc3c99f9f0d98b8b7b3ffbe74879af0fe9d311475091c
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Aug2007_d3dx9_35_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10F6C6.tmp\Aug2007_d3dx9_35_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 8cef7d8a56d1ea4c015efa7ea238b390
SHA256: b02aa5edc212124f329e56db2064cf760b0963aa406a17de1aae2dcea24dd34c
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: f35ef33d4ab93d5730493a6275c7f7cd
SHA256: 661f75a662c4f209c9cc5da1fa47c33d6ecdfabe702ca9d8ad86e91d998f7ffb
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2007_d3dx10_34_x86.cab
compressed
MD5: a603a208b84e622e5d6c108ca8b792d4
SHA256: 9f66dcfc3e24604de72aed57f805b5b9953a68b8976ab58ee7852b5fc370ce60
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10F4C2.tmp\Jun2007_d3dx10_34_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Jun2007_d3dx10_34_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: c7a98c3ee63d27ddf59e7af0f78e9ab6
SHA256: 2721a6537abab5aa60ae333ea117da8af25f9658d4ef822ad1d5d04049bbefe8
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2007_d3dx9_34_x86.cab
compressed
MD5: 173a58584e446b8265b22723ca87cb68
SHA256: 9838c9eb61fa0d7c06d409949cf3af96d45f51d946322009a12468dc8c237112
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: a1e4983b5576f5a24f724420090e5dde
SHA256: daf0cb2a8f922746b3ed5c11e7f939e95498ac0063dd80027fabefa4bbaea78a
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10F0CA.tmp\Jun2007_d3dx9_34_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Jun2007_d3dx9_34_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2007_d3dx10_33_x86.cab
compressed
MD5: d7e338e73456a436e40b1c80ee6f8d19
SHA256: d6424840fb36d4132ea26687f071258cef978317ca6c973b022e2e0508d57af0
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: a9fe6f2ff85e3b963896119a296ea035
SHA256: 6975d59f61823c9941057883dba52f8c850be7a3c3a42fe11c0e119438cd2731
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 1cb18aa992fc089b3147f4c871b423a6
SHA256: b9a994decb9e90c6e7b4587bdd807c0671eaaf9cc465b1811db97fb08510711a
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10EF05.tmp\Apr2007_d3dx10_33_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Apr2007_d3dx10_33_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: c3be7d781654a593f3d7c47d4784e4bc
SHA256: f2189c8a015168b2d3e843b597a778daf81a146b81d0b8a7ae735c6411ce51ec
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 1d9267e021b04328a3c0a21e85199109
SHA256: 0c1e4047ef915c080b66d25d475f7b2c09d8d7ec564ea72a64740a203b508bf6
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
dat
MD5: d3c0ba08211bea7a290588c3fe944fe6
SHA256: 1f5a69914c1dac1386344b8a754dd007169b20e37837d86b36ab273fe5914002
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2007_d3dx9_33_x86.cab
compressed
MD5: 1bfc5fe4cc815537fce95397e0f622e5
SHA256: 348d0873170b81b4795a07acb55ddfc88c30927c0fe0991747c14a0c16405f58
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10EB4C.tmp\Apr2007_d3dx9_33_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Apr2007_d3dx9_33_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Dec2006_d3dx9_32_x86.cab
compressed
MD5: ee203c3de50bee324d776961ba2ad19a
SHA256: 253d63c608d56ae154d5eea210dde93f9924e27bb21069fb8108b0ff31672016
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 932adfa0d4635411dc3bc56bfb48dad5
SHA256: be06ce8d52bd5106bd3912c861e60d436e5a7a746fe99a4b3589f34b0a3e3670
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 21813dc7b01a164e9fbea74572c847ad
SHA256: d26f6c1b85055b83360000fb8653bfa62aed82ad77930b6bae755bf012cdd4ed
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10E783.tmp\Dec2006_d3dx9_32_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Dec2006_d3dx9_32_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Oct2006_d3dx9_31_x86.cab
compressed
MD5: f074a046666299233ab8dfb49f937739
SHA256: 4c2f62d52cf95aea752cc0c38891d5e8ad9567856726ae16d5a97741ff98066e
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: a1bec06bc0f7b6851811b3270ab64bb6
SHA256: 587de69902c515876e60d0293f6ebececc90bab7a072faff5d6494f30dd1c805
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 8c404a6c881c04dc3215aacce71f33ce
SHA256: 7f2387a398238e38a0715afdee4b9127870bb845b9cebf1a960f13c92eeafdd8
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10E4D4.tmp\Oct2006_d3dx9_31_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Oct2006_d3dx9_31_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: c0e4e96ab7c817d857481c424c0784cc
SHA256: cb0190d17662b4e1b4d6b4cb2d931c960874e0a9568a9ca377a0f873a1e9fbb9
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 97bfbad35623652c46383d77c04679a3
SHA256: f7f6598c989fb96f8b5851c481a3e0d8556dc7f47b1637ef4ce74850b6a9a58c
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2006_d3dx9_30_x86.cab
compressed
MD5: 5d515f31a45ab947c2bdebee06a2b179
SHA256: 74c13bb8108957030c7eef86183344914f287a5fa9044ddc4e0e347f90bc2f19
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10E224.tmp\Apr2006_d3dx9_30_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Apr2006_d3dx9_30_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 09cd5d0242b67fe0dbd3db552abfec98
SHA256: b86be5152bc44d204cd56c7e1c0afd42d981e34f0f7c24919dc9e2ee8d8e55e9
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 66a6b469ca68660abf058991001591a3
SHA256: ca6c9c8b0774d96300b06ed5ab88c06010a9b7183afbf1bee82c8be67e19be92
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2006_d3dx9_29_x86.cab
compressed
MD5: 30078e2c8e2c9b1ca9828f2b521d5a71
SHA256: 74da74f1c2142f210c7488686e278d894230773882d994948c63bff7bc6c50e7
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10DF94.tmp\Feb2006_d3dx9_29_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Feb2006_d3dx9_29_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 8e4ed27fd945bad8756327fca6e6aafe
SHA256: 1efc87451bd54aa5fcda9958ed308e5a69e58ec73662c6878af3e94b720dc713
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 8d784502d6291aa3e2c8c38bd963cf68
SHA256: bd9764f44bce6a0e255b7f8424a84b4abbc4fa4af61e947fa060c809cefc0c5e
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Dec2005_d3dx9_28_x86.cab
compressed
MD5: 174cbfbc3e79ad27132c85c4006f8941
SHA256: 9ce5d659ffd2bccd7b81278ae15666751a4dd8395978b243da4efa0487b68771
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Dec2005_d3dx9_28_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10DCF4.tmp\Dec2005_d3dx9_28_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 6df9553c1ffa36228b4c9b8f820b39a5
SHA256: 82127f7a5b884e4b1b264b5ebd5344212037287dd581d4d35a40bb463a5b0599
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 8ddfd4029c352834017cef6fa5b3e284
SHA256: 5c9e70263a2732193c6221e79a6e911480a4daafdf756d845899185002563158
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2005_d3dx9_27_x86.cab
compressed
MD5: d195b717962f5534f07eb5696f30b859
SHA256: 6ace05658b2c7ee988e3474931a7f10a9a986a5a9d19fe9d7babf9423fbd73e2
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Aug2005_d3dx9_27_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10DA64.tmp\Aug2005_d3dx9_27_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 173c0c761f45e79d541d21393881d187
SHA256: ede9394ff17af84597bed970264c31175fa55d4d4b6f4ef168257ffcac766a16
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: f40219838715db375a42d91184acd688
SHA256: 21a45a44b5e2bb54cf22532d130388a36c1b86bfb68b2398a3fd16c4421b7e2a
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2005_d3dx9_26_x86.cab
compressed
MD5: cb8d3200002e954d8f2ab535748e9b80
SHA256: c7cbff27f473ae616e897bc84d8e2b16a4991b2a0c652fed0f3c6d1817d2b66f
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10D7D4.tmp\Jun2005_d3dx9_26_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Jun2005_d3dx9_26_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 77c8e146dec220d4367fd9383070403a
SHA256: ebf11ccd90b2cbc5b1b2015250a8b89934a7febf726a6db5779c0d3f0cd7d710
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 5daf34bfec53ec64e9d7a3dd4dac6fb3
SHA256: b56af343ccf5e99563e00b7965a4b5f4d847dd2f9565f958bd49585b3f8fd42f
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2005_d3dx9_25_x86.cab
compressed
MD5: 4fb26408cf01fb75ffb906f0164a79e1
SHA256: a2698d4e26399a3f98bb003879c4c3e8373da8a11f028632288ddd3253d266db
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10D534.tmp\Apr2005_d3dx9_25_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Apr2005_d3dx9_25_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: bcaf0c921ca0b086064c65bff00b3a46
SHA256: 0d11956b6a3afa58e0f491db77ab4559dc3b52e344b772ea8fec38ab29d3fcea
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: f6d1d4b10408ec6f8a42331d6882f343
SHA256: 4f9ecc35c8d6f4b0964c11aad4329983ef6152643f6fa9493c42eb81c08b6fd0
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2005_d3dx9_24_x86.cab
compressed
MD5: 0a7f1f452705e38c7736c0d626947886
SHA256: 8b1b62632b150a97f540c731949f6e2d08bd96cbc32b20ab4dfb6aaae4f1ac41
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Feb2005_d3dx9_24_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10D284.tmp\Feb2005_d3dx9_24_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 40056fa2479a15bcd009fd99260ab40c
SHA256: f4400472dd901b5f9b7d50eb9f327f36e326e90a701d716e031fc3f9f3b798d1
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: f497eb7fbf98c866687fb6839a5fe540
SHA256: 64fd2024215710d6a79a1f9b3a4d81cb08fd6c2a08cfe5ac96c2418731f33283
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2010_xaudio_x86.cab
compressed
MD5: 9d2da3b1055120af7c2995896f5d51ed
SHA256: 7b4332207563beba1103744b6db5399ad150e9e6838f9d5a71497e7eb3645ebf
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: df5f567ecc5c9e61f51b29fd4015ca78
SHA256: bc97ff90d64c7c4845102eb5c2e2942a597c7f2b1ba1baa4d1cd48cbb4528f0b
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Jun2010_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10D14C.tmp\Jun2010_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 3b07fc4165a87e9f9444283e3c5004dd
SHA256: 32b019d61dbe5f9b4de782541cce6c737d594a510cabdab3cde80c71fc8bfd7f
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: ad983c383b7365045b049f17ad03a83c
SHA256: 21d943a720bb406c9b53e3ac06baf40e1c32bbf9f4eb39dd4aeb776bf46f8b99
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2010_xact_x86.cab
compressed
MD5: 02da71bfa4764677ffcb9dcc62714418
SHA256: 354c2e579ed00b391dd5d8be91b0f45115e7c232ed1b842747830be0fd26e915
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Jun2010_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10D0CF.tmp\Jun2010_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2010_xaudio_x86.cab
compressed
MD5: 5da6e4a80fa53568d2fdde31cbff2979
SHA256: 281bb0e12f617e9ae7fe3301a7d4a08201b377caa0311a886e8cddc2526f734a
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Feb2010_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CFF4.tmp\Feb2010_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: e358d10849ef5c68b73a8c1bd988d6b9
SHA256: 99f92794646030c424997db5b21e5e1ce3163e3532c573ac0dbe951d6a59f627
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 945706e71edf5c4ea887131875c05ce4
SHA256: fae4c2ed4bdc0d6ca7043c98f5c15a0ab00c840871699700eb74d0c8d515ab62
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2010_xact_x86.cab
compressed
MD5: 5cf3585c99a59319ac10e18cc92f0024
SHA256: 0ba00c41443639dea9b816fa2608088ccef5dbe850531dff4c1e7993804b0b60
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Feb2010_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CF77.tmp\Feb2010_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2010_x3daudio_x86.cab
compressed
MD5: ed093ce20bddc7c42ede4daf772ed5aa
SHA256: 7fbf09682fd15d721ff2c5cb110b5ffcf5982cd2dd8d72b708cf3cd0bc4fa250
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CF29.tmp\Feb2010_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Feb2010_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_xaudio_x86.cab
compressed
MD5: 8f123149337dc74532e1b64ca50520ef
SHA256: 149cc8a12e90681f879ac209e46c12a4abe24bf2f3e338e1f6739446433ab1e5
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CE4E.tmp\Aug2009_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Aug2009_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 9a8ab67bb0ab195cf033df8910ff8316
SHA256: 700b1cc7cd654419af9e4011365156df5d9a3c32fed214ecf5db0e1c6d20af2f
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_xact_x86.cab
compressed
MD5: 7291df2d7014d3319f58ddef6d589cdc
SHA256: 0192f3ecabc07fe226d9f63fad98f5d480b204d8839b92e953a34aa2565423a9
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 2836cbce09cee5bc66449e05ccc302df
SHA256: 785fb26c55c27089354dace7f98fa007f2fb681c1ae183796015f53d7806c4d0
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CDE1.tmp\Aug2009_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Aug2009_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_xaudio_x86.cab
compressed
MD5: 61c7a3bd64c42b0e66f9f597e3ccfe7b
SHA256: edfcd459618b11d264a83757f2bdfeb9a795132df3fb607eaab2e421212f4363
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Mar2009_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CCE7.tmp\Mar2009_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_xact_x86.cab
compressed
MD5: 5cc975ac008c328267012f461a70e342
SHA256: 2c61222f2996817cdb10a76866bfa1e6462af74a3adf2ae01f6e753993b40f68
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CC79.tmp\Mar2009_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Mar2009_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 72a267a35e6cf0e270e21c89ad65b4ff
SHA256: 39d69c8742c9924b3424091dfb161fe5602e2ec247ea258c2401ea7d9bf096ac
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_x3daudio_x86.cab
compressed
MD5: 091e6730378d71a960b9973fe6f8c6b6
SHA256: fe25e5f2bcd5e231c79d2817cb659239ea5685390044ad3ff8bbbbad5ecba4a8
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 060e435e7c16a9075292039e8ff1454b
SHA256: 6b3a683e62cd3f5c2124ab858d90746c85a02cddc106426a8fa1f29315783e7f
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Mar2009_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CC1C.tmp\Mar2009_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_xaudio_x86.cab
compressed
MD5: 67331679bf1ca84f671e97a29dabe4ca
SHA256: 2910788f89f051e888fb1f3f3e9c3823ee61e6b7f795091358642136abed49db
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Nov2008_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CB51.tmp\Nov2008_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_xact_x86.cab
compressed
MD5: 1749c4a36be386caa30453ea66101605
SHA256: 4757689ef0358230a67479a307770dd5276838cf97edac9792aea8c011b94f5b
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Nov2008_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CAC4.tmp\Nov2008_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_x3daudio_x86.cab
compressed
MD5: 3c6dc9ef9edbb67a2788ffe14fba22f3
SHA256: aee61ffdeda87b2690c9a162c3cdbcff5f3191bec882149cefbdbbc107a2eec9
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10CA76.tmp\Nov2008_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Nov2008_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 5d85c6ab575096638697d3a1bcd59020
SHA256: 0057d48c5b47ab37db7d3e4f03006af786d049ed44ef9d57df89c66250fbb31d
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 437f0a90b173d6ee49017305b6098f49
SHA256: b0c2df020809aea3eb769f04d070866492f630a135f49bc6f6f61bd414fca4e9
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2008_xaudio_x86.cab
compressed
MD5: 4676e68e459c9bf222305bbe0f4384d5
SHA256: 4e1525054eb942b11237488d508069cb33495fe9dfe4ad077c22f3931d0726c3
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C9AB.tmp\Aug2008_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Aug2008_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2008_xact_x86.cab
compressed
MD5: eddde2269aaafed1c8e9587660c19ac1
SHA256: 9e7d4386f51d66b641711bdaa7367e400d9ab56b0041faa483ce2d6e6f4afcd2
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C91E.tmp\Aug2008_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Aug2008_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_xaudio_x86.cab
compressed
MD5: 780265c576b5d8f42fb75486e703b180
SHA256: a55d0aa37aaf3e033462bc3a4c1ce92ec88495c6e666051a70b03a9435e54018
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Jun2008_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C814.tmp\Jun2008_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: b7a6739c5e53691739d6c179201b461f
SHA256: c44f5b09d12289235ddb6ce44ba466e7ca9dc7340f057a02f3216a39873fecbf
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 9e4af59598e2b5c349817c231ac3c442
SHA256: 58e41e360d8ca6e1cd55e202e8643a664da8cb70f6d13fd9e816a232cb8ba0ef
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_xact_x86.cab
compressed
MD5: 54f867a86e2c7458785d7cb6324fd652
SHA256: 24bcd116766845a0955c5d85998d903df3f9ad3c6366a62d89d06d2346c07d8f
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Jun2008_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C797.tmp\Jun2008_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_x3daudio_x86.cab
compressed
MD5: 432238ef413d8d476077d4fe5d5adb9b
SHA256: cd52c71cf099ea7cbb8ae8e946d8f96c546abe8804f0cf7915b9fce9d2ed4143
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C749.tmp\Jun2008_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Jun2008_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_xaudio_x86.cab
compressed
MD5: b473bc75a74561dd4d4c7ec6e5354d25
SHA256: a2c6a22f2f5231328c3fad844231df1c38c64f91300ce6cf48c58209b2d35a7a
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C66F.tmp\Mar2008_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Mar2008_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 8637f460adcc0d7462900ee4fee7d2f1
SHA256: 863a43a1d474d72c9ca46ebc497b462229077ce18f84d513139b6914e0c989bf
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 1957039cf7eab4cc1390dc0570ecf773
SHA256: daa5a59fc7af3eed6ddcd9c688a10de714231abba4b9b92786415a7bf47fdcad
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_xact_x86.cab
compressed
MD5: f60bdac60a94f43fc9ab65dd0ca91fbb
SHA256: 518f409ee2f036b41a223e43d98fdb23113ec86e6f2f12c3db8a2d4b24dfc025
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C5E2.tmp\Mar2008_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Mar2008_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_x3daudio_x86.cab
compressed
MD5: 134733d617277a62db3e6ff830cc5043
SHA256: b97abfad95dec464b5c40df2c694f939500609cf796a4561c5a7a8743358621a
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Mar2008_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C5A3.tmp\Mar2008_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2007_xact_x86.cab
compressed
MD5: 9f523d41620fa73b256c68f4b23d91fd
SHA256: 0a1165240b23378e855975a3d3a1f2cb174fc066daec8aca1d522c62f019866f
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Nov2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C507.tmp\Nov2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2007_x3daudio_x86.cab
compressed
MD5: 42e4a0e056e36d63c9d3ceec19b7285c
SHA256: d32e52db08d77aadafb05724167fa159323ae1efe62f7000d1b07e52413d18bb
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Nov2007_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C4B9.tmp\Nov2007_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: fc42ef2c8153e07ee8d83804b5c518cb
SHA256: 031f8e0ebf3416813f17871a6e3a4d619c7073d6ece3c7e7184a5be4896acc3e
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2007_xact_x86.cab
compressed
MD5: 8ae81116d961191457a1247a6b756b62
SHA256: 3ae5fa28b601827d636ba21ef1737ec3a4fac762646674e8937932edee4864ef
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: f97a1d9d749ff86de21fb1cd87b1cd0b
SHA256: 92a7264daec95c9d7819834046a98bd2612d85a57b587608c28a5ee26b9a3c3b
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C42C.tmp\Aug2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Aug2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2007_xact_x86.cab
compressed
MD5: 72051b7f4832dc7a67a9ba9f1b41e5c1
SHA256: 53d10f6fb49862d2d3257406505fa7e4fbf9049a348b367508c48366c220392d
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C390.tmp\Jun2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Jun2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2007_xinput_x86.cab
compressed
MD5: 37ce8fc84fd5c79135b258b51280ba2d
SHA256: fca066ad1912eb9698798e3a4e0b9723868411fe058775afe343f600eaea93cc
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C313.tmp\Apr2007_xinput_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Apr2007_xinput_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2007_xact_x86.cab
compressed
MD5: fbbf2ed3f2806c55dba75d6ef1f1974e
SHA256: 78a32869d67a52389e0268e23e082c11243ec26f26d8e067d9f73f4d9efda10a
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C229.tmp\Apr2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Apr2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 3092fdf338c35c83acfc3a783ee4e2a2
SHA256: ca5ddb097d0454819c7f7c957cc462467b33c3d4735b19cdec85bbac94610309
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: d66c3e7cdb909282ece8bf397ff2579f
SHA256: e190fa496ce3f025ff7be4fcee67b61a5bdd0d092604afb4b9508bc0f5237392
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2007_xact_x86.cab
compressed
MD5: fa1b6ce3d092330034e85a8445d6bbbc
SHA256: 901b1f75d8c128ddfa602d54ac7ec0a4e4bbfd8f3f2e8920e97b7d3d677883d3
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C17D.tmp\Feb2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Feb2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Dec2006_xact_x86.cab
compressed
MD5: cb7d7afc67feedcb6963c41ee0a4d136
SHA256: 95fd76c80dc00672f0fad7404afeb7122a77f04c77e8bb10c247c6e140ed48c3
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C100.tmp\Dec2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Dec2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Dec2006_d3dx10_00_x86.cab
compressed
MD5: 74b10649e083503ec0c0040c1ff7a5c6
SHA256: 0bfb802908686afadbe3e723388b82d83324e02d900913bd3f251f82be1f1351
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Dec2006_d3dx10_00_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10C054.tmp\Dec2006_d3dx10_00_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: f58524236e6da91270552dd5e512ba4a
SHA256: 3527c8183b5ac199b5958e29ec268fb8b38483d708b69314005741ba397bc243
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 9d17aa3a97129b846e245a9132585dc2
SHA256: e08a2ef6a791d155cfaf6eb348e22c625f43618d55a76ad4acddd3235ad92efd
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Oct2006_xact_x86.cab
compressed
MD5: b09acf9e6d262d2f69ac2f040a60fa4e
SHA256: 3e5c1ee4a3579af819d56107477ff7e89d14d92c004d8bda32fcd6854292fa3a
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10BFB8.tmp\Oct2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Oct2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2006_xinput_x86.cab
compressed
MD5: 3cf8796dc72fcaa7b7571ac9f256bc33
SHA256: 4b6939d271f69e4ecfbae69f34fb3268a36066a2f264710a791599bf4773f7db
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10BF6A.tmp\Aug2006_xinput_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Aug2006_xinput_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2006_xact_x86.cab
compressed
MD5: c3c06a83d4e2f3b238df8befc8ec6522
SHA256: 39faafde245efa464cbc2d88efd0b88690d95d7182c35bbbdb22ce50a3051249
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Aug2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10BEDD.tmp\Aug2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 260dbae027d485acafa2e31d960fc921
SHA256: 00c27271a5002b872631fbaf25a52a94feb5ef09ba0fe21288fad0a3312ef11e
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 977786eb18b1900c9cd4928c1ed755fa
SHA256: fbad3cb68b7dd2936945c568361669da8751d25c46ec3232bae5a083c8d61429
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2006_xact_x86.cab
compressed
MD5: d40c7d1b2741c3f4ff3e03d46c73761d
SHA256: e20679e920fa233375f15d991f3890cf7fdb29fdc213ac32bb808dd96d79eb5b
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\Jun2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10BE41.tmp\Jun2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2006_xinput_x86.cab
compressed
MD5: ac3ac5e22c2c9122af11ec7495d22570
SHA256: 755520722a9b01c3eafa6b5dd7c1951fc1ce06275e55fbf24f54874c707bda56
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Apr2006_xinput_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10BD85.tmp\Apr2006_xinput_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2006_xact_x86.cab
compressed
MD5: 068f0a0fd3049474fc029e07d061aae9
SHA256: 80a2e2e13bf12b97728f6fc42b04827b704dd56a383142919116637cf4ed3f27
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Apr2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10BD08.tmp\Apr2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 35d061aa0935768433f0216165a17b34
SHA256: 51dea7067fce907fb0e7e7c9c316a6877257361f8d1d206e7dd7df4678596696
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2006_xact_x86.cab
compressed
MD5: 15b452e4f90466391943496a841788f6
SHA256: 70e3220d9ef2b4a987ee5063f229ce44d237599c7cd5556735bbf38a59b3de48
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS10BC7C.tmp\Feb2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Feb2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 1f4d7396c67100831bfcfe21e6d9a6d5
SHA256: 490dadbf706586858227ceed82d40727fbe6b4d03bb7f705a8369d2807dccb2a
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 148bdbf2fae9983f465f267a77f24714
SHA256: 0e532d20949d5ef44bce8883218db06791fe7dbc2c347324463f28a77c032844
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 91a543639397ee3f1aad39e300561a34
SHA256: 8cd1d96e81463a60232d6379fa510ddaf42d33889ba52521f406e08ccbaf4a99
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: afa7c8d0b4484ee98282ae8174cb7733
SHA256: 4052e7f2cc12b4912fd6b6a71d15f88b1baf3a134e841c5d51417cfa2d6a16e4
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: b35ca57fef8be5386003ea8ca557bd95
SHA256: 130d282714b498bc397a3b1c1ffe3cc33ff04379cd183f2d1bc61a72786aa3d5
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 793634b8a035d96d0aa60074eb2ecb84
SHA256: 6d9832f0cd0332ccc5a1a9ed94ad3732fb67bfd1f08538baf899715e400d2d5c
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: de7c905ac14b5b9f53a4eb26f4c929d6
SHA256: 1037e77bc3b326a16810476ba4ff30b61311bbda21272b0e97e99dc71d9d4932
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 9760f43636ad5b6b8bce4d0b011192e0
SHA256: 4e80fc7fefc22ccadce8df47a44ebc4d1facb818e1a7129e5141386f580fc36f
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 8e440067b7b07a7fb340ebf576409749
SHA256: 36c8bb36a6175b42add01a8864448fe247c8586792ae9b1eb126e45319381990
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxupdate.cif
text
MD5: b36d3f105d18e55534ad605cbf061a92
SHA256: c6c5e877e92d387e977c135765075b7610df2500e21c16e106a225216e6442ae
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxupdate.inf
text
MD5: e6a74342f328afa559d5b0544e113571
SHA256: 93f5589499ee4ee2812d73c0d8feacbbcfe8c47b6d98572486bc0eff3c5906ca
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.cif
ini
MD5: 6456318e550b5af3bea955a6faac3351
SHA256: 676cb687e68b990e69bcfca6b18390a8d89a7fdc302f3f36f0abd1d68e0c8c26
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 968e6dc16f4e63f10de5516d8e24b897
SHA256: 6aecb1b32b56aad1f1c5d35af736985036da790063d51a33a172c799c43d51c8
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 219f268241fc41d29530c3e01d5440c2
SHA256: 0e57e7ac5945c087e6acf99b954aa799289d2d6620639f5f712b621f191e1962
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\DXI9B67.tmp
ini
MD5: 6456318e550b5af3bea955a6faac3351
SHA256: 676cb687e68b990e69bcfca6b18390a8d89a7fdc302f3f36f0abd1d68e0c8c26
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 44749a470b14b1524a613f350f0db678
SHA256: e8fe48ec4b601be2dc140507676eec22e92f83d152576f9875ca0ed6db03d311
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\dxupdate.cab
compressed
MD5: 8f7d54a83655e8f2afe6d188a57b0102
SHA256: 3071c3a2b879d12977e81a19b86c64cd48c8bf285790e289d35eae82bc342c45
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS1099F0.tmp\dxupdate.cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\dxupdate[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 4a0f4aaaf2e162e1a95fab4a0722e0ed
SHA256: 8b6157d610a10c031d9315c1bf5d6c28e766f67fcaa290ffd4ec49bae5ad3881
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: cc85d7649546d3c0b1607f761b73fec2
SHA256: e1c85577fee77b7535af5918de16479d5b38f08d7aadbf1b3613d275c7797920
2744
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 339b850a48babb8772ddb6bb4b274cea
SHA256: deea569b1823565ed503da0958d1c41432294c364baf2807e1e33416440d8adb
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_d3dx11_42_x86.cab
compressed
MD5: 3f0df13380977588fc6ad961e56af849
SHA256: 17a10b561995c45ebebdd0e6a999ea7be5bbc59ff80cb7395b36b8c1215c39e7
2744
dxwsetup.exe
C:\Windows\INF\setupapi.app.log
text
MD5: df9b45cf69ea8877283601af9bfe4cde
SHA256: 5c1400dab462cc542f6d12f2157efe7dd30c8ef352d1125493ce437681118d9b
2744
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\Aug2009_d3dx11_42_x86[1].cab
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\directx\websetup\SET669C.tmp
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\system32\directx\websetup\SET669B.tmp
––
MD5:  ––
SHA256:  ––
2744
dxwsetup.exe
C:\Windows\msdownld.tmp\AS1123E0.tmp\Aug2009_d3dx11_42_x86.cab
––
MD5:  ––
SHA256:  ––
2088
directx.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.cif
ini
MD5: 4bf39e4bb4a0595ef7a83ce93279f1dc
SHA256: 32e1bd2e381f27d9815a5ee44f82b000da3522e205e26991d2b490a527e62c30
2088
directx.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.inf
ini
MD5: ad8982eaa02c7ad4d7cdcbc248caa941
SHA256: d63c35e9b43eb0f28ffc28f61c9c9a306da9c9de3386770a7eb19faa44dbfc00
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_d3dx10_42_x86.cab
compressed
MD5: 9874fee186ce25db85ba38b072763257
SHA256: c50d305b768fa8cd65fc885d56f06c37d8880c87a635bc1fe0d8f9f674837b6e
2744
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: bd5ffb9fa0785c8e9203a54aa1728abc
SHA256: 9c485f55b5ce38cc65bbb335237f5908d926075fad6c597e08dd34e9d33831ea

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
69
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxupdate.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2006_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xinput_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2006_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xinput_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Oct2006_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2006_d3dx10_00_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2006_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2007_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_xinput_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2007_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2007_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2007_x3daudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2007_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_x3daudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_xaudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2008_x3daudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2008_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2008_xaudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2008_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2008_xaudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2008_x3daudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2008_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2008_xaudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2009_x3daudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2009_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2009_xaudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2009_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2009_xaudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2010_x3daudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2010_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2010_xaudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2010_xact_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2010_xaudio_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2005_d3dx9_24_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2005_d3dx9_25_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2005_d3dx9_26_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2005_d3dx9_27_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2005_d3dx9_28_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2006_d3dx9_29_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_d3dx9_30_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Oct2006_d3dx9_31_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2006_d3dx9_32_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_d3dx9_33_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_d3dx10_33_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2007_d3dx9_34_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2007_d3dx10_34_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2007_d3dx9_35_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2007_d3dx10_35_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2007_d3dx9_36_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2007_d3dx10_36_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_d3dx9_37_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_d3dx10_37_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2008_d3dx9_38_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2008_d3dx10_38_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2008_d3dx9_39_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2008_d3dx10_39_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2008_d3dx9_40_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2008_d3dx10_40_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2009_d3dx9_41_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2009_d3dx10_41_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2009_d3dx9_42_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2009_d3dx10_42_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2009_d3dx11_42_x86.cab unknown
compressed
whitelisted
2744 dxwsetup.exe GET –– 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2009_d3dcsx_42_x86.cab unknown
––
––
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2744 dxwsetup.exe 2.18.233.19:80 Akamai International B.V. –– whitelisted

DNS requests

Domain IP Reputation
download.microsoft.com 2.18.233.19
whitelisted

Threats

PID Process Class Message
2744 dxwsetup.exe Generic Protocol Command Decode SURICATA STREAM excessive retransmissions

Debug output strings

Process Message
dxwsetup.exe DLL_PROCESS_DETACH
dxwsetup.exe DLL_PROCESS_DETACH
dxwsetup.exe DLL_PROCESS_DETACH
dxwsetup.exe DLL_PROCESS_DETACH