| File name: | Virtual.Display.Driver-v24.12.24-setup-x64.exe |
| Full analysis: | https://app.any.run/tasks/f50c1a9b-9fca-4b66-b330-a4017fcc0f93 |
| Verdict: | Malicious activity |
| Analysis date: | April 20, 2025, 07:29:37 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections |
| MD5: | 500DFC199F7076DBDECF621B842A4139 |
| SHA1: | D90F3572FB768445AEAE823DB1F735326955E9A3 |
| SHA256: | 755DFE973615DA34E904157D5D0962C8C14E74AB6BC5191A91720BB17D464515 |
| SSDEEP: | 98304:irq3BdwO2ev9HvzPrMREgPgXByALyXfJp8i7MXcG8JBjvul5DcuSdIln0tpaJS9q:iad |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:07:12 07:26:53+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 685056 |
| InitializedDataSize: | 374272 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa83bc |
| OSVersion: | 6.1 |
| ImageVersion: | - |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | VirtualDisplay |
| FileDescription: | Virtual Display Driver Setup |
| FileVersion: | |
| LegalCopyright: | Copyright © 2022-2024 MikeTheTech |
| OriginalFileName: | |
| ProductName: | Virtual Display Driver |
| ProductVersion: | 24.12.24 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 744 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 840 | "C:\VirtualDisplayDriver\Companion\VDDSysTray.exe" | C:\VirtualDisplayDriver\Companion\VDDSysTray.exe | Virtual.Display.Driver-v24.12.24-setup-x64.tmp | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 900 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1116 | nefconw.exe --install-driver --inf-path ""C:\VirtualDisplayDriver"\MttVDD.inf" | C:\VirtualDisplayDriver\nefconw.exe | cmd.exe | ||||||||||||
User: admin Company: Nefarius Software Solutions e.U. Integrity Level: HIGH Description: Nefarius' Device Console Utility Exit code: 0 Version: 1.10.0.0 Modules
| |||||||||||||||
| 1128 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1228 | nefconw.exe --remove-device-node --hardware-id Root\MttVDD --class-guid 4d36e968-e325-11ce-bfc1-08002be10318 | C:\VirtualDisplayDriver\nefconw.exe | — | cmd.exe | |||||||||||
User: admin Company: Nefarius Software Solutions e.U. Integrity Level: HIGH Description: Nefarius' Device Console Utility Exit code: 6 Version: 1.10.0.0 Modules
| |||||||||||||||
| 1452 | "C:\WINDOWS\system32\cmd.exe" /C ""C:\VirtualDisplayDriver\install.bat" 1 "Best GPU (Auto)" "C:\VirtualDisplayDriver"" | C:\Windows\System32\cmd.exe | — | Virtual.Display.Driver-v24.12.24-setup-x64.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3024 | "C:\VirtualDisplayDriver\Companion\VDDSysTray.exe" | C:\VirtualDisplayDriver\Companion\VDDSysTray.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 3096 | nefconw.exe --create-device-node --hardware-id Root\MttVDD --class-name Display --class-guid 4D36E968-E325-11CE-BFC1-08002BE10318 | C:\VirtualDisplayDriver\nefconw.exe | — | cmd.exe | |||||||||||
User: admin Company: Nefarius Software Solutions e.U. Integrity Level: HIGH Description: Nefarius' Device Console Utility Exit code: 0 Version: 1.10.0.0 Modules
| |||||||||||||||
| 3156 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{5a0ea4a9-cce8-c245-9370-70c0efef13d5}\MttVDD.inf" "9" "426b4eb0b" "00000000000001E0" "WinSta0\Default" "00000000000000F0" "208" "C:\VirtualDisplayDriver" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\MikeTheTech\VirtualDisplayDriver |
| Operation: | write | Name: | VDDPATH |
Value: C:\VirtualDisplayDriver | |||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\MikeTheTech\VirtualDisplayDriver |
| Operation: | write | Name: | InstalledBy |
Value: Installer | |||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualDisplayDriver_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.3.3 | |||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualDisplayDriver_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\VirtualDisplayDriver | |||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualDisplayDriver_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\VirtualDisplayDriver\ | |||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualDisplayDriver_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: VDDbyMTT | |||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualDisplayDriver_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualDisplayDriver_is1 |
| Operation: | write | Name: | Inno Setup: Setup Type |
Value: custom | |||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualDisplayDriver_is1 |
| Operation: | write | Name: | Inno Setup: Selected Components |
Value: vdd,companionapp,scripts,scripts\changevddreslution,scripts\changevddrefreshrate,scripts\rotatevdd,scripts\scalevdd,scripts\makevddprimary,scripts\winpasscript,scripts\togglevddpower,scripts\enlidilo | |||
| (PID) Process: | (5428) Virtual.Display.Driver-v24.12.24-setup-x64.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirtualDisplayDriver_is1 |
| Operation: | write | Name: | Inno Setup: Deselected Components |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4400 | Virtual.Display.Driver-v24.12.24-setup-x64.exe | C:\Users\admin\AppData\Local\Temp\is-BPVHC.tmp\Virtual.Display.Driver-v24.12.24-setup-x64.tmp | executable | |
MD5:C8E8223C24286061011C3437EB0367A4 | SHA256:309719A422FE447DE604EAB3580BC80051DBED7309DA116B4A93A23AF209C9C3 | |||
| 4428 | Virtual.Display.Driver-v24.12.24-setup-x64.exe | C:\Users\admin\AppData\Local\Temp\is-8LG01.tmp\Virtual.Display.Driver-v24.12.24-setup-x64.tmp | executable | |
MD5:C8E8223C24286061011C3437EB0367A4 | SHA256:309719A422FE447DE604EAB3580BC80051DBED7309DA116B4A93A23AF209C9C3 | |||
| 5428 | Virtual.Display.Driver-v24.12.24-setup-x64.tmp | C:\VirtualDisplayDriver\unins000.exe | executable | |
MD5:27BB990F6A10E951C963A598043BFD25 | SHA256:236787F2ABB0EEDC4682BFB39C8C0F66B198E6A9B1C21E4E49B781AC7D813EC5 | |||
| 4944 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_0ti4n0u0.emd.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 4944 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_u1jgnjje.tw5.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5428 | Virtual.Display.Driver-v24.12.24-setup-x64.tmp | C:\Users\admin\AppData\Local\VDDInstaller\getlist.bat | text | |
MD5:885CB3163277E80D452338E1CC78F4FB | SHA256:A8F1EDCF195036F6A0A036A8BD75FC543D86E5B4DA76AA2B28CB6447EAA04F45 | |||
| 5428 | Virtual.Display.Driver-v24.12.24-setup-x64.tmp | C:\Users\admin\AppData\Local\VDDInstaller\gpulist.txt | text | |
MD5:5B915BF53D7408FCDD726B27AE7C76C1 | SHA256:F06D32D5834E05822B61765D197F77E186220051D2D5934819CD481D1AD4BFED | |||
| 5428 | Virtual.Display.Driver-v24.12.24-setup-x64.tmp | C:\VirtualDisplayDriver\is-DFIAE.tmp | executable | |
MD5:27BB990F6A10E951C963A598043BFD25 | SHA256:236787F2ABB0EEDC4682BFB39C8C0F66B198E6A9B1C21E4E49B781AC7D813EC5 | |||
| 4944 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:DAC27F4161B12EF45F83D1E55EA4226F | SHA256:FEB8ADA7F9C19B4E4FF372B691EB5CFD597D52C62C36D1E50B3A1C3FCA734CAD | |||
| 5428 | Virtual.Display.Driver-v24.12.24-setup-x64.tmp | C:\VirtualDisplayDriver\is-U2FAG.tmp | binary | |
MD5:EECE77B6053312FA8D1CFFFAFBD1C3FE | SHA256:6A4E1186F812B838BF59C5ADE22485FC37834BA3318688195121AEE2F4B20BBB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.66:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.24.231.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1056 | SIHClient.exe | GET | 200 | 23.38.73.129:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1056 | SIHClient.exe | GET | 200 | 23.38.73.129:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
840 | VDDSysTray.exe | GET | 301 | 67.205.23.181:80 | http://vdd.mikethetech.com/Version-Control/release.txt | unknown | — | — | unknown |
2924 | SearchApp.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3024 | VDDSysTray.exe | GET | 301 | 67.205.23.181:80 | http://vdd.mikethetech.com/Version-Control/release.txt | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.164.66:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.31.129:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 184.24.231.245:80 | ocsp.digicert.com | AKAMAI-AS | IT | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1056 | SIHClient.exe | 4.175.87.197:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1056 | SIHClient.exe | 23.38.73.129:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |