| download: | SetupExitLag_v3119.exe |
| Full analysis: | https://app.any.run/tasks/2ad5d5ce-bb88-4f73-a790-d9866e2738c3 |
| Verdict: | Malicious activity |
| Analysis date: | June 03, 2020, 18:38:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 8A2A3E020250C606B1675AC75250DAF7 |
| SHA1: | C7BB5E7FEBDB5D05EED6FDEEF5CC2C3EF4308357 |
| SHA256: | 9BFB0657B32A43A10C922D51D98A6E0393C71684F4028D316CF40AE903824017 |
| SSDEEP: | 393216:x68lA3wJ8TQKpMLZfHua7l3Jm9Csj3vaB7PcPaTs2SrE1:xKgJc5w/u+QCYCkSoNrc |
| .exe | | | Win32 Executable Delphi generic (57.2) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (18.2) |
| .exe | | | Win16/32 Executable Delphi generic (8.3) |
| .exe | | | Generic Win/DOS Executable (8) |
| .exe | | | DOS Executable Generic (8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:06 16:39:04+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 138752 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x117dc |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | ExitLag |
| FileDescription: | ExitLag Setup |
| FileVersion: | |
| LegalCopyright: | |
| ProductName: | ExitLag |
| ProductVersion: | 3 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 06-Apr-2016 14:39:04 |
| Detected languages: |
|
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | ExitLag |
| FileDescription: | ExitLag Setup |
| FileVersion: | - |
| LegalCopyright: | - |
| ProductName: | ExitLag |
| ProductVersion: | 3 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0050 |
| Pages in file: | 0x0002 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x000F |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x001A |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000100 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 8 |
| Time date stamp: | 06-Apr-2016 14:39:04 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0000F244 | 0x0000F400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.37521 |
.itext | 0x00011000 | 0x00000F64 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.7322 |
.data | 0x00012000 | 0x00000C88 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.29672 |
.bss | 0x00013000 | 0x000056BC | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x00019000 | 0x00000E04 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.59781 |
.tls | 0x0001A000 | 0x00000008 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x0001B000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.204488 |
.rsrc | 0x0001C000 | 0x0001FDBC | 0x0001FE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.69128 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.13965 | 1580 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 3.64126 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.20079 | 16936 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 2.91763 | 67624 | Latin 1 / Western European | English - United States | RT_ICON |
4091 | 2.56031 | 104 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4092 | 3.25287 | 212 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4093 | 3.26919 | 164 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4094 | 3.33268 | 684 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4095 | 3.34579 | 844 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4096 | 3.28057 | 660 | Latin 1 / Western European | UNKNOWN | RT_STRING |
advapi32.dll |
comctl32.dll |
kernel32.dll |
oleaut32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 376 | "C:\Users\admin\AppData\Local\Temp\is-ARDHO.tmp\SetupExitLag_v3119.tmp" /SL5="$2012C,15525745,206336,C:\Users\admin\Desktop\SetupExitLag_v3119.exe" | C:\Users\admin\AppData\Local\Temp\is-ARDHO.tmp\SetupExitLag_v3119.tmp | — | SetupExitLag_v3119.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 868 | "C:\Program Files\ExitLag\ExitLag.exe" | C:\Program Files\ExitLag\ExitLag.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1064 | "C:\Users\admin\Desktop\SetupExitLag_v3119.exe" /SPAWNWND=$20132 /NOTIFYWND=$2012C | C:\Users\admin\Desktop\SetupExitLag_v3119.exe | SetupExitLag_v3119.tmp | ||||||||||||
User: admin Company: ExitLag Integrity Level: HIGH Description: ExitLag Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 1128 | "C:\Program Files\ExitLag\exitlag_reboot_required.exe" | C:\Program Files\ExitLag\exitlag_reboot_required.exe | — | SetupExitLag_v3119.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1884 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2352 | "C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\tools\i386\certinst.exe" C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\root.cer | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\tools\i386\certinst.exe | — | SetupExitLag_v3119.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2440 | "C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\DriverCacheCleaner.exe" | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\DriverCacheCleaner.exe | — | SetupExitLag_v3119.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2564 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{61868a06-bcd4-2196-cd15-1e6309b53874}\ndextlag_lwf.inf" "0" "69e81846b" "000004C0" "WinSta0\Default" "000004DC" "208" "C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\lwf\win7\i386" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2684 | "C:\Users\admin\AppData\Local\Temp\is-8VD99.tmp\SetupExitLag_v3119.tmp" /SL5="$2013E,15525745,206336,C:\Users\admin\Desktop\SetupExitLag_v3119.exe" /SPAWNWND=$20132 /NOTIFYWND=$2012C | C:\Users\admin\AppData\Local\Temp\is-8VD99.tmp\SetupExitLag_v3119.tmp | SetupExitLag_v3119.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2836 | "C:\Program Files\ExitLag\ExitLag.exe" | C:\Program Files\ExitLag\ExitLag.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3010 Modules
| |||||||||||||||
| (PID) Process: | (2684) SetupExitLag_v3119.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 7C0A000014250241D639D601 | |||
| (PID) Process: | (2684) SetupExitLag_v3119.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: F311C0B9B3D1962108974141A74905AC7DB14ACBA1274B01E90BD3394081753F | |||
| (PID) Process: | (2684) SetupExitLag_v3119.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1884) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\vf-9IUUU.gzc\QevirePnpurPyrnare.rkr |
Value: 0000000000000000000000004E000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000 | |||
| (PID) Process: | (1884) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | HRZR_PGYFRFFVBA |
Value: 00000000420000005300000016EE25000B0000001A00000057BE0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000010000024E9ED017990C577B8006900000069000010000050E9ED01C4F6C4770000690000000000580269000002690064E9ED016C19C5770D00000000026900580269002CEBED0128EBED01000008009786217614E8ED0114EAED01D8E9ED0115E1C077C7670800FEFFFFFF8B8DC477108BC47701000000010000000000000004EAED01CCE9ED01E8E9ED012C8AC375010000000000000004EAED013F8AC375ED1805AB000000006CEFED0102000000FFFFFFFF0000000000000000000000000000E96FACE9ED01485F9B0050EEED01B514C5754D7B2BDFFEFFFFFF3F8AC375A36CC375A589C375651F05AB6CEFED0111000000483D3200403D32006CEFED017CEA0000C05704AB2CEAED018291D2767CEAED01EC430000FC5704AB40EAED01B69CD276F04311024C06000058EAED01603F110264EAED01789CD2763691D27611000000483D3200403D320000EBED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010B0000001A00000057BE0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000010000024E9ED017990C577B8006900000069000010000050E9ED01C4F6C4770000690000000000580269000002690064E9ED016C19C5770D00000000026900580269002CEBED0128EBED01000008009786217614E8ED0114EAED01D8E9ED0115E1C077C7670800FEFFFFFF8B8DC477108BC47701000000010000000000000004EAED01CCE9ED01E8E9ED012C8AC375010000000000000004EAED013F8AC375ED1805AB000000006CEFED0102000000FFFFFFFF0000000000000000000000000000E96FACE9ED01485F9B0050EEED01B514C5754D7B2BDFFEFFFFFF3F8AC375A36CC375A589C375651F05AB6CEFED0111000000483D3200403D32006CEFED017CEA0000C05704AB2CEAED018291D2767CEAED01EC430000FC5704AB40EAED01B69CD276F04311024C06000058EAED01603F110264EAED01789CD2763691D27611000000483D3200403D320000EBED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010B0000001A00000057BE0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000010000024E9ED017990C577B8006900000069000010000050E9ED01C4F6C4770000690000000000580269000002690064E9ED016C19C5770D00000000026900580269002CEBED0128EBED01000008009786217614E8ED0114EAED01D8E9ED0115E1C077C7670800FEFFFFFF8B8DC477108BC47701000000010000000000000004EAED01CCE9ED01E8E9ED012C8AC375010000000000000004EAED013F8AC375ED1805AB000000006CEFED0102000000FFFFFFFF0000000000000000000000000000E96FACE9ED01485F9B0050EEED01B514C5754D7B2BDFFEFFFFFF3F8AC375A36CC375A589C375651F05AB6CEFED0111000000483D3200403D32006CEFED017CEA0000C05704AB2CEAED018291D2767CEAED01EC430000FC5704AB40EAED01B69CD276F04311024C06000058EAED01603F110264EAED01789CD2763691D27611000000483D3200403D320000EBED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED01 | |||
| (PID) Process: | (2352) certinst.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\3C9EF70FC04EF0F94FF7C8B3FD14AC98E2F9A404 |
| Operation: | write | Name: | Blob |
Value: 0300000001000000140000003C9EF70FC04EF0F94FF7C8B3FD14AC98E2F9A40420000000010000003F0500003082053B30820423A00302010202100E4AA136F842CF069FA2B1D13B47803D300D06092A864886F70D01010505003073310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D313230300603550403132944696769436572742048696768204173737572616E636520436F6465205369676E696E672043412D31301E170D3135303933303030303030305A170D3138313030343132303030305A308183310B30090603550406130256473110300E06035504081307546F72746F6C613112301006035504071309526F616420546F776E31263024060355040A131D4D61696E6C696E65204E657420486F6C64696E6773204C696D69746564312630240603550403131D4D61696E6C696E65204E657420486F6C64696E6773204C696D6974656430820122300D06092A864886F70D01010105000382010F003082010A0282010100A46DC66517DBBDBF031F53BD6D7E83FE56A812DE44AB1AB8808E80B70F189AA81817F459B70A4DA4A2BCF187781E72621801EA2EB06328AD8CDCBFDAC90790D61445AC84999F9F8F834B2272BC90F95082B9DD87060BABBB48DADF1CDFC511746991866726FD5681FBFF11D032F29906CF07199ED2F9608D2D8B16014DF5E1C09EC11B3748D235B0B70C7A1DD37A938C9F8F031A7AAAA535759C460744CC9B429A70FC3B3454A814DCDAD2D4D0CFAB2992DDF484AD85DDBD52C4D86D25B6DEEABAABDE33F9A3EB74DBD472BFEEB75D22DB89315B422E26DEFCF8C713832DA4062349C68E3D1FE8B76FE340FBC0B55B1429B8B79A4755D82EBBB4D3AB17018D770203010001A38201B8308201B4301F0603551D23041830168014974803EB15086BB9B25823CC942EF1C665D2648E301D0603551D0E04160414FAD831E9141F3CA65BE6D36D9820545085201D04300E0603551D0F0101FF04040302078030130603551D25040C300A06082B0601050507030330690603551D1F04623060302EA02CA02A8628687474703A2F2F63726C332E64696769636572742E636F6D2F68612D63732D32303131612E63726C302EA02CA02A8628687474703A2F2F63726C342E64696769636572742E636F6D2F68612D63732D32303131612E63726C304B0603551D2004443042303706096086480186FD6C0301302A302806082B06010505070201161C68747470733A2F2F7777772E64696769636572742E636F6D2F4350533007060567810C010430818606082B06010505070101047A3078302406082B060105050730018618687474703A2F2F6F6373702E64696769636572742E636F6D305006082B060105050730028644687474703A2F2F636163657274732E64696769636572742E636F6D2F4469676943657274486967684173737572616E6365436F64655369676E696E6743412D312E637274300C0603551D130101FF04023000300D06092A864886F70D010105050003820101005D31723227361D4D6FE738208F585EA3771A40C1B0EFAFCAAD239DAFE052B820DBB7D217899DADDF9407B4DD8232962F9B3E640D4B0AC84E040F7C113C47E5BDED0CD96A1B98D240B8F9E29553124C5A4FA406E45384A46F968FE772EA05D69FC0AF258A38217B9E68710585C5655F8A0E72DD713C22765F8A4D36B4819ABFA0E69FC27EFC0FDA7F3E51311FE11E048CE2868AB4D8C33912548FCC6D54AE173CA292002D2238B67D68CB3B56A474F32BC7AD8E6E75A86E2618C0C08FD9006257E32EF3DE6E579806C1D9EBDC0ABD4D80D161946295FF2D7E75938AF270F110C856BBDD66B3CAE08B8EAF895520BF9B68E4E18315BA59DB9DAAE06FF1D897417F | |||
| (PID) Process: | (3812) snetcfg.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus |
| Operation: | write | Name: | setupapi.dev.log |
Value: 4096 | |||
| (PID) Process: | (1884) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\vf-9IUUU.gzc\JvacxSvygre\gbbyf\v386\pregvafg.rkr |
Value: 0000000000000000000000005E000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000 | |||
| (PID) Process: | (1884) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | HRZR_PGYFRFFVBA |
Value: 00000000420000005300000074EE25000B0000001A00000057BE0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000010000024E9ED017990C577B8006900000069000010000050E9ED01C4F6C4770000690000000000580269000002690064E9ED016C19C5770D00000000026900580269002CEBED0128EBED01000008009786217614E8ED0114EAED01D8E9ED0115E1C077C7670800FEFFFFFF8B8DC477108BC47701000000010000000000000004EAED01CCE9ED01E8E9ED012C8AC375010000000000000004EAED013F8AC375ED1805AB000000006CEFED0102000000FFFFFFFF0000000000000000000000000000E96FACE9ED01485F9B0050EEED01B514C5754D7B2BDFFEFFFFFF3F8AC375A36CC375A589C375651F05AB6CEFED0111000000483D3200403D32006CEFED017CEA0000C05704AB2CEAED018291D2767CEAED01EC430000FC5704AB40EAED01B69CD276F04311024C06000058EAED01603F110264EAED01789CD2763691D27611000000483D3200403D320000EBED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010B0000001A00000057BE0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000010000024E9ED017990C577B8006900000069000010000050E9ED01C4F6C4770000690000000000580269000002690064E9ED016C19C5770D00000000026900580269002CEBED0128EBED01000008009786217614E8ED0114EAED01D8E9ED0115E1C077C7670800FEFFFFFF8B8DC477108BC47701000000010000000000000004EAED01CCE9ED01E8E9ED012C8AC375010000000000000004EAED013F8AC375ED1805AB000000006CEFED0102000000FFFFFFFF0000000000000000000000000000E96FACE9ED01485F9B0050EEED01B514C5754D7B2BDFFEFFFFFF3F8AC375A36CC375A589C375651F05AB6CEFED0111000000483D3200403D32006CEFED017CEA0000C05704AB2CEAED018291D2767CEAED01EC430000FC5704AB40EAED01B69CD276F04311024C06000058EAED01603F110264EAED01789CD2763691D27611000000483D3200403D320000EBED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010B0000001A00000057BE0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000010000024E9ED017990C577B8006900000069000010000050E9ED01C4F6C4770000690000000000580269000002690064E9ED016C19C5770D00000000026900580269002CEBED0128EBED01000008009786217614E8ED0114EAED01D8E9ED0115E1C077C7670800FEFFFFFF8B8DC477108BC47701000000010000000000000004EAED01CCE9ED01E8E9ED012C8AC375010000000000000004EAED013F8AC375ED1805AB000000006CEFED0102000000FFFFFFFF0000000000000000000000000000E96FACE9ED01485F9B0050EEED01B514C5754D7B2BDFFEFFFFFF3F8AC375A36CC375A589C375651F05AB6CEFED0111000000483D3200403D32006CEFED017CEA0000C05704AB2CEAED018291D2767CEAED01EC430000FC5704AB40EAED01B69CD276F04311024C06000058EAED01603F110264EAED01789CD2763691D27611000000483D3200403D320000EBED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED01 | |||
| (PID) Process: | (3812) snetcfg.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3000 | SetupExitLag_v3119.exe | C:\Users\admin\AppData\Local\Temp\is-ARDHO.tmp\SetupExitLag_v3119.tmp | executable | |
MD5:— | SHA256:— | |||
| 2684 | SetupExitLag_v3119.tmp | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\root.cer | der | |
MD5:— | SHA256:— | |||
| 2684 | SetupExitLag_v3119.tmp | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\lwf\vista\i386\ndextlag.cat | cat | |
MD5:— | SHA256:— | |||
| 2684 | SetupExitLag_v3119.tmp | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\lwf\vista\amd64\ndextlag.cat | cat | |
MD5:— | SHA256:— | |||
| 2684 | SetupExitLag_v3119.tmp | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\lwf\vista\amd64\ndextlag_lwf.inf | binary | |
MD5:— | SHA256:— | |||
| 2684 | SetupExitLag_v3119.tmp | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\DriverCacheCleaner.exe | executable | |
MD5:— | SHA256:— | |||
| 2684 | SetupExitLag_v3119.tmp | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\lwf\vista\amd64\ndextlag.sys | executable | |
MD5:— | SHA256:— | |||
| 2684 | SetupExitLag_v3119.tmp | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\lwf\vista\i386\ndextlag_lwf.inf | binary | |
MD5:— | SHA256:— | |||
| 2684 | SetupExitLag_v3119.tmp | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\lwf\win10\amd64\ndextlag.sys | executable | |
MD5:— | SHA256:— | |||
| 2684 | SetupExitLag_v3119.tmp | C:\Users\admin\AppData\Local\Temp\is-9VHHH.tmp\WinpkFilter\lwf\win10\amd64\ndextlag.cat | cat | |
MD5:— | SHA256:— | |||