File name:

wps_wid.cid-179914454.1735277789.exe

Full analysis: https://app.any.run/tasks/6917144e-a042-4d55-83d7-16381e8ceac6
Verdict: Malicious activity
Analysis date: December 27, 2024, 06:06:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
wps
qrcode
maldoc-17
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

C45689F8E17CAD73431F6585B309B9D8

SHA1:

43984B0EA7D3CFA847FC0557FB8C0BF53F644A8E

SHA256:

BF2821EA11776C6B48D08106E401F4F23FF703392937FDCA3A6E47773D4B9454

SSDEEP:

98304:bns0Xwyuvk5cA5bK3dmTtySEHmRqvpQuaYwhL9+FOsWbxFiETcHJJp4ubuExNgt9:cbkUeT1L5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops known malicious document

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
  • SUSPICIOUS

    • WPS mutex has been found

      • wps_wid.cid-179914454.1735277789.exe (PID: 1136)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3132)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
    • Starts another process probably with elevated privileges via RUNAS.EXE

      • runas.exe (PID: 1040)
    • Reads settings of System Certificates

      • wps_wid.cid-179914454.1735277789.exe (PID: 1136)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3132)
    • Executable content was dropped or overwritten

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
    • The process drops C-runtime libraries

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
    • Process drops legitimate windows executable

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
    • There is functionality for taking screenshot (YARA)

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
    • Write to the desktop.ini file (may be used to cloak folders)

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
    • The process creates files with name similar to system file names

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
  • INFO

    • Checks supported languages

      • wps_wid.cid-179914454.1735277789.exe (PID: 1136)
      • wmpnscfg.exe (PID: 2900)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3132)
    • Reads the computer name

      • wps_wid.cid-179914454.1735277789.exe (PID: 1136)
      • wmpnscfg.exe (PID: 2900)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3132)
    • Reads the software policy settings

      • wps_wid.cid-179914454.1735277789.exe (PID: 1136)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3132)
    • Process checks computer location settings

      • wps_wid.cid-179914454.1735277789.exe (PID: 1136)
    • Reads the machine GUID from the registry

      • wps_wid.cid-179914454.1735277789.exe (PID: 1136)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3132)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2900)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3132)
    • The sample compiled with english language support

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
    • Sends debugging messages

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3132)
    • The sample compiled with chinese language support

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
    • The sample compiled with japanese language support

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
    • Creates files or folders in the user directory

      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3180)
      • 29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe (PID: 3132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:11:11 15:54:01+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 4085248
InitializedDataSize: 1803776
UninitializedDataSize: -
EntryPoint: 0x2756f5
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 12.9.0.18826
ProductVersionNumber: 12.9.0.18826
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Zhuhai Kingsoft Office Software Co.,Ltd
FileDescription: WPS Office Setup
FileVersion: 12,9,0,18826
InternalName: konlinesetup_xa
LegalCopyright: Copyright©2024 Kingsoft Corporation. All rights reserved.
OriginalFileName: konlinesetup_xa.exe
ProductName: WPS Office
ProductVersion: 12,9,0,18826
MIMEType: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start runas.exe no specs wps_wid.cid-179914454.1735277789.exe wmpnscfg.exe no specs 29368139f1709fe83757f8d2d53918f6-15_setup_xa_mui_free.exe.500.2083.exe 29368139f1709fe83757f8d2d53918f6-15_setup_xa_mui_free.exe.500.2083.exe

Process information

PID
CMD
Path
Indicators
Parent process
1040"C:\Windows\System32\runas.exe" /user:administrator C:\Users\admin\Desktop\wps_wid.cid-179914454.1735277789.exeC:\Windows\System32\runas.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Run As Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\runas.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1136C:\Users\admin\Desktop\wps_wid.cid-179914454.1735277789.exeC:\Users\admin\Desktop\wps_wid.cid-179914454.1735277789.exe
runas.exe
User:
Administrator
Company:
Zhuhai Kingsoft Office Software Co.,Ltd
Integrity Level:
HIGH
Description:
WPS Office Setup
Version:
12,9,0,18826
Modules
Images
c:\users\admin\desktop\wps_wid.cid-179914454.1735277789.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2900"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3132"C:\Users\admin\Desktop\wps_download\29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe" -downpower -installCallByOnlineSetup -defaultOpen -defaultOpenPdf -asso_pic_setup -createIcons -pinTaskbar -curlangofinstalledproduct="en_US" -D="C:\Users\Administrator\AppData\Local\Kingsoft\WPS Office" -notautostartwps="C:\Users\Administrator\AppData\Local\Kingsoft\WPS Office" -enableSetupMuiPkg="C:\Users\Administrator\AppData\Local\Kingsoft\WPS Office" -appdata="C:\Users\Administrator\AppData\Roaming" -msgwndname=wpssetup_message_118EB0 -curinstalltemppath=C:\Users\ADMINI~1\AppData\Local\Temp\wps\~118569\C:\Users\admin\Desktop\wps_download\29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
explorer.exe
User:
admin
Company:
Zhuhai Kingsoft Office Software Co.,Ltd
Integrity Level:
MEDIUM
Description:
WPS Install Application
Version:
12,2,0,19307
Modules
Images
c:\users\admin\desktop\wps_download\29368139f1709fe83757f8d2d53918f6-15_setup_xa_mui_free.exe.500.2083.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
3180C:\Users\admin\Desktop\wps_download\29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe -installCallByOnlineSetup -defaultOpen -defaultOpenPdf -asso_pic_setup -createIcons -pinTaskbar -curlangofinstalledproduct=en_US -D="C:\Users\Administrator\AppData\Local\Kingsoft\WPS Office" -notautostartwps -enableSetupMuiPkg -appdata="C:\Users\Administrator\AppData\Roaming"C:\Users\admin\Desktop\wps_download\29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
wps_wid.cid-179914454.1735277789.exe
User:
Administrator
Company:
Zhuhai Kingsoft Office Software Co.,Ltd
Integrity Level:
HIGH
Description:
WPS Install Application
Version:
12,2,0,19307
Modules
Images
c:\users\admin\desktop\wps_download\29368139f1709fe83757f8d2d53918f6-15_setup_xa_mui_free.exe.500.2083.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
Total events
21 575
Read events
21 492
Write events
78
Delete events
5

Modification events

(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\kingsoft\kwpsonlinesetup
Operation:writeName:infoGuid
Value:
3D37253F7F9F49079C62443B84EBEEDA
(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\kingsoft\kwpsonlinesetup
Operation:writeName:infoHdid
Value:
ef5b71b54c73293d35808c4ca7c1f048
(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\kingsoft\kwpsonlinesetup
Operation:writeName:onlinesetup_penetrate_id_type
Value:
web
(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\kingsoft\kwpsonlinesetup
Operation:writeName:onlinesetup_penetrate_id
Value:
cid-179914454.1735277789
(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\2\52C64B7E
Operation:delete keyName:(default)
Value:
(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\2
Operation:delete keyName:(default)
Value:
(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\qagentrt.dll,-10
Value:
System Health Authentication
(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\System32\wuaueng.dll,-400
Value:
Windows Update
(PID) Process:(1136) wps_wid.cid-179914454.1735277789.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124
Value:
Document Encryption
Executable files
229
Suspicious files
1 018
Text files
2 417
Unknown types
13

Dropped files

PID
Process
Filename
Type
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\prereadimages_qing.txt
MD5:
SHA256:
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\default\106.pngimage
MD5:83F3FA276CD75A78053372E32D83DB86
SHA256:F183BCB33059BDAC07040F210AF6ABEB94D2E42DBD3703815893D7AF2D6E49A2
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\default\background.pngimage
MD5:27B9C403FA884EBF4EA0CC23D69A42D7
SHA256:5479C612C47D5CD3EBDAA11EBF897B6E84D95C364587133E03F778450A51412D
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\default\background_choose_mode.pngimage
MD5:DFCD86EE5D01A98036E7FAB9634513B7
SHA256:4E595667FFBC31321ED210169F37374123291623ADD8575D6BDD78A4026DA9C2
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\ja_JP\1003.pngimage
MD5:2D808B698701B15B33BEC04710A4F7EF
SHA256:3CFD7FA737826AC37D44B79F688B4DD2FE7E61B790A3EB5B90081B7F77446549
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\ja_JP\1004.pngimage
MD5:46B7F99F4DF13B446570B0157A75C5EE
SHA256:CCEDD187E6A9F4A703395A539F0598E44C985F544EABFCDA96909ED66AE6BA0D
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\ja_JP\1002.pngimage
MD5:16AEFB6C1454D76A589385767C066433
SHA256:E42774D8B3819C19F13294B917A93330104BCF33D269B1B8CB46A2865D97061D
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\default\background_msgbox_xa.pngimage
MD5:B43A492B0223096B73DE9A2B29D631B5
SHA256:AAFA36EF3DD914A1F00E0A4C9E7683E1AB2F160F0D5A88C8206C78EBA61DDF6F
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\default\background_xa.pngimage
MD5:367C2059F78AB2055CF62C373A94876D
SHA256:89B8259727FA09E45DF119A1B812A3343EB0B7A5F86EB58D952934472E8F02B0
318029368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exeC:\Users\Administrator\AppData\Local\Temp\wps\~118569\CONTROL\default\background_oem.pngimage
MD5:481E9EC6D63B0D8979A5D5B4595134A5
SHA256:AF82FD27077BD7FF4892881A75E7A41780C7FDB9C274615C7AF96AC3A3CA38E1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
16
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1136
wps_wid.cid-179914454.1735277789.exe
216.58.206.46:443
google.com
GOOGLE
US
whitelisted
1136
wps_wid.cid-179914454.1735277789.exe
90.84.175.86:443
params.wps.com
Orange
FR
unknown
1136
wps_wid.cid-179914454.1735277789.exe
104.16.83.69:443
wdl1.pcfg.cache.wpscdn.com
CLOUDFLARENET
unknown
3180
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
216.58.206.46:443
google.com
GOOGLE
US
whitelisted
3132
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
216.58.206.46:443
google.com
GOOGLE
US
whitelisted
3132
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
90.84.175.86:443
params.wps.com
Orange
FR
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
www.google-analytics.com
  • 216.58.206.46
whitelisted
params.wps.com
  • 90.84.175.86
whitelisted
api.wps.com
  • 90.84.175.86
whitelisted
wdl1.pcfg.cache.wpscdn.com
  • 104.16.83.69
  • 104.16.84.69
unknown

Threats

No threats detected
Process
Message
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
[kscreen] isElide:0 switchRec:0 switchRecElide:1
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
QLayout: Attempting to add QLayout "" to QWidget "m_BrandAreaWidget", which already has a layout
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
QLayout: Attempting to add QLayout "" to QWidget "", which already has a layout
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
29368139f1709fe83757f8d2d53918f6-15_setup_XA_mui_Free.exe.500.2083.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout