File name:

MultiCommander_x64_14.5.0.3054.exe

Full analysis: https://app.any.run/tasks/4adda4ed-1ac4-4be9-b5f2-d5ff6076b309
Verdict: Malicious activity
Analysis date: December 24, 2024, 04:09:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

93702D901BF006055C85B9B5E64130C5

SHA1:

1C964B9D5E8EECC363F393415444B5155FA3520E

SHA256:

C4DD40EED596E669B27859501311433657FC6AA713EAFB76E289917762188498

SSDEEP:

98304:H5UWxg9HTlOGDUsIiRUcVL7k71/pM7MwBw79ShQcR00bf6SQcTIGA2omuQd7c1dz:H5bmlH9yrjK9HbkxtYdft+8bldWy9g+0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
    • Application launched itself

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
    • The process creates files with name similar to system file names

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
    • Executable content was dropped or overwritten

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
    • Creates a software uninstall entry

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
    • Drops 7-zip archiver for unpacking

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
  • INFO

    • Create files in a temporary directory

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
    • Checks supported languages

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
      • vlc.exe (PID: 3632)
    • Reads the computer name

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
      • vlc.exe (PID: 3632)
    • Process checks whether UAC notifications are on

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
    • Process checks computer location settings

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3040)
    • Creates files in the program directory

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
    • Creates files or folders in the user directory

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
    • The sample compiled with english language support

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
    • The sample compiled with swedish language support

      • MultiCommander_x64_14.5.0.3054.exe (PID: 3540)
    • Manual execution by a user

      • OpenWith.exe (PID: 4044)
      • notepad.exe (PID: 1156)
      • OpenWith.exe (PID: 4400)
      • OpenWith.exe (PID: 1480)
      • OpenWith.exe (PID: 5684)
      • OpenWith.exe (PID: 4580)
      • OpenWith.exe (PID: 5968)
      • OpenWith.exe (PID: 2632)
      • OpenWith.exe (PID: 2976)
      • OpenWith.exe (PID: 5448)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 4044)
      • OpenWith.exe (PID: 5684)
      • OpenWith.exe (PID: 4400)
      • OpenWith.exe (PID: 1480)
      • OpenWith.exe (PID: 4580)
      • OpenWith.exe (PID: 5968)
      • OpenWith.exe (PID: 2976)
      • OpenWith.exe (PID: 2632)
      • OpenWith.exe (PID: 5448)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 1156)
      • OpenWith.exe (PID: 2976)
    • The process uses the downloaded file

      • OpenWith.exe (PID: 2976)
    • Sends debugging messages

      • vlc.exe (PID: 3632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:02 03:20:05+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 120320
UninitializedDataSize: 1024
EntryPoint: 0x30fb
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 14.5.0.3054
ProductVersionNumber: 14.5.0.3054
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
Comments: Installer for Multi Commander
CompanyName: Mathias Svensson
FileDescription: Multi Commander installation
FileVersion: 14.5.0.3054
LegalCopyright: 2016 Mathias Svensson
ProductName: Multi Commander
ProductVersion: 14.5.0.3054
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
13
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start multicommander_x64_14.5.0.3054.exe multicommander_x64_14.5.0.3054.exe notepad.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs openwith.exe no specs vlc.exe

Process information

PID
CMD
Path
Indicators
Parent process
1156"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\__README_DO_NOT_MODIFY__.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
1480"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\GetSelectedFilesAndProcessThem.udcC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2632"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\MapNetworkDrive.udcC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2976"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\Copy_NoDlg_NewQueue.udcC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3040"C:\Users\admin\Desktop\MultiCommander_x64_14.5.0.3054.exe" C:\Users\admin\Desktop\MultiCommander_x64_14.5.0.3054.exe
explorer.exe
User:
admin
Company:
Mathias Svensson
Integrity Level:
MEDIUM
Description:
Multi Commander installation
Version:
14.5.0.3054
Modules
Images
c:\users\admin\desktop\multicommander_x64_14.5.0.3054.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3540"C:\Users\admin\Desktop\MultiCommander_x64_14.5.0.3054.exe" /UAC:801FA /NCRC C:\Users\admin\Desktop\MultiCommander_x64_14.5.0.3054.exe
MultiCommander_x64_14.5.0.3054.exe
User:
admin
Company:
Mathias Svensson
Integrity Level:
HIGH
Description:
Multi Commander installation
Version:
14.5.0.3054
Modules
Images
c:\users\admin\desktop\multicommander_x64_14.5.0.3054.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3632"C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\Desktop\Copy_NoDlg_NewQueue.udc"C:\Program Files\VideoLAN\VLC\vlc.exe
OpenWith.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Version:
3.0.11
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4044"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\CalculateSHA1HashForAllSelected.udcC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4400"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\RunNotepadWithParamters.udcC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4580"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\EnterSameFolderInBothPanel.udcC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
6 314
Read events
6 306
Write events
8
Delete events
0

Modification events

(PID) Process:(3540) MultiCommander_x64_14.5.0.3054.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiCommander x64
Operation:writeName:DisplayName
Value:
MultiCommander (x64)
(PID) Process:(3540) MultiCommander_x64_14.5.0.3054.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiCommander x64
Operation:writeName:UninstallString
Value:
C:\Program Files\MultiCommander (x64)\Uninstall MultiCommander.exe
(PID) Process:(3540) MultiCommander_x64_14.5.0.3054.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiCommander x64
Operation:writeName:InstallMode
Value:
1
(PID) Process:(3540) MultiCommander_x64_14.5.0.3054.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiCommander x64
Operation:writeName:InstallPath
Value:
C:\Program Files\MultiCommander (x64)
(PID) Process:(3540) MultiCommander_x64_14.5.0.3054.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiCommander x64
Operation:writeName:Publisher
Value:
Mathias Svensson
(PID) Process:(3540) MultiCommander_x64_14.5.0.3054.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiCommander x64
Operation:writeName:HelpLink
Value:
Http://multicommander.com
(PID) Process:(3540) MultiCommander_x64_14.5.0.3054.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiCommander x64
Operation:writeName:DisplayIcon
Value:
"C:\Program Files\MultiCommander (x64)\MultiCommander.EXE",0
(PID) Process:(3540) MultiCommander_x64_14.5.0.3054.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiCommander x64
Operation:writeName:DisplayVersion
Value:
14.5.0.3054
Executable files
35
Suspicious files
31
Text files
88
Unknown types
0

Dropped files

PID
Process
Filename
Type
3040MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nsk6333.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
3040MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nsk6333.tmp\System.dllexecutable
MD5:56A321BD011112EC5D8A32B2F6FD3231
SHA256:BB6DF93369B498EAA638B0BCDC4BB89F45E9B02CA12D28BCEDF4629EA7F5E0F1
3040MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nsk6333.tmp\nsDialogs.dllexecutable
MD5:F832E4279C8FF9029B94027803E10E1B
SHA256:4CD17F660560934A001FC8E6FDCEA50383B78CA129FB236623A9666FCBD13061
3040MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nsk6333.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
3040MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nsk6333.tmp\InstallOptions.dllexecutable
MD5:D753362649AECD60FF434ADF171A4E7F
SHA256:8F24C6CF0B06D18F3C07E7BFCA4E92AFCE71834663746CFAA9DDF52A25D5C586
3040MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nsk6333.tmp\UAC.dllexecutable
MD5:88AD3FD90FC52AC3EE0441A38400A384
SHA256:E58884695378CF02715373928BB8ADE270BAF03144369463F505C3B3808CBC42
3540MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nslA5BA.tmp\UAC.dllexecutable
MD5:88AD3FD90FC52AC3EE0441A38400A384
SHA256:E58884695378CF02715373928BB8ADE270BAF03144369463F505C3B3808CBC42
3540MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nslA5BA.tmp\ioSpecial.iniini
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
3540MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nslA5BA.tmp\InstallOptions.dllexecutable
MD5:D753362649AECD60FF434ADF171A4E7F
SHA256:8F24C6CF0B06D18F3C07E7BFCA4E92AFCE71834663746CFAA9DDF52A25D5C586
3540MultiCommander_x64_14.5.0.3054.exeC:\Users\admin\AppData\Local\Temp\nslA5BA.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
17
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4328
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
204
104.126.37.153:443
https://www.bing.com/threshold/xls.aspx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
4328
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4328
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
104.126.37.177:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
www.bing.com
  • 104.126.37.177
  • 104.126.37.130
  • 104.126.37.171
  • 104.126.37.131
  • 104.126.37.185
  • 104.126.37.162
  • 104.126.37.163
  • 104.126.37.179
  • 104.126.37.178
whitelisted
self.events.data.microsoft.com
  • 52.168.112.67
whitelisted

Threats

No threats detected
Process
Message
vlc.exe
main libvlc debug: revision 3.0.11-0-gdc0c5ced72
vlc.exe
main libvlc debug: configured with ../extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-dvdread' '--enable-shout' '--enable-goom' '--enable-caca' '--enable-qt' '--enable-skins2' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=x86_64-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' 'host_alias=x86_64-w64-mingw32' 'PKG_CONFIG_LIBDIR=/home/jenkins/workspace/vlc-release/windows/vlc-release-win32-x64/contrib/x86_64-w64-mingw32/lib/pkgconfig'
vlc.exe
main libvlc debug: min period: 1 ms, max period: 1000000 ms
vlc.exe
main libvlc debug: VLC media player - 3.0.11 Vetinari
vlc.exe
main libvlc debug: Copyright © 1996-2020 the VideoLAN team
vlc.exe
main libvlc debug: using multimedia timers as clock source
vlc.exe
main libvlc debug: searching plug-in modules
vlc.exe
main libvlc debug: loading plugins cache file C:\Program Files\VideoLAN\VLC\plugins\plugins.dat
vlc.exe
main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
vlc.exe
main libvlc debug: plug-ins loaded: 494 modules