URL:

https://storage.levelleap.com/nina/clients/msnp/patched-installer/msn/escargot-msn-7.5.0324-es.zip

Full analysis: https://app.any.run/tasks/54995d5b-9159-4a1e-a351-6e0c74618283
Verdict: Malicious activity
Analysis date: November 14, 2023, 17:01:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
SHA1:

A5ED04E293863588E1FFFACD41B1011E869DA4DF

SHA256:

CCF94B769C36CBA85B9E9BAEF1DEEE07AA2F97A52E8123BA165CEAEE13A3EAE9

SSDEEP:

3:N8cMECX5821m/9O4GSBuXKILlWDkTc:2cMr5l1c+SBuXT5WAw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 3672)
      • msnsearch.exe (PID: 2396)
    • Scans artifacts that could help determine the target

      • msiexec.exe (PID: 3672)
      • msnmsgr.exe (PID: 2988)
    • Creates a writable file the system directory

      • msiexec.exe (PID: 3672)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • msiexec.exe (PID: 3648)
      • msiexec.exe (PID: 3672)
      • msnsearch.exe (PID: 2396)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1852)
    • Changes the Home page of Internet Explorer

      • msiexec.exe (PID: 3672)
    • Reads the Internet Settings

      • mtbs.exe (PID: 604)
      • msnmsgr.exe (PID: 2988)
    • Reads Microsoft Outlook installation path

      • mtbs.exe (PID: 604)
    • Reads Internet Explorer settings

      • mtbs.exe (PID: 604)
    • Changes the title of the Internet Explorer window

      • msiexec.exe (PID: 3672)
    • Checks Windows Trust Settings

      • msnmsgr.exe (PID: 2988)
    • Reads settings of System Certificates

      • msnmsgr.exe (PID: 2988)
    • Reads security settings of Internet Explorer

      • msnmsgr.exe (PID: 2988)
    • Connects to unusual port

      • msnmsgr.exe (PID: 2988)
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 3404)
      • msnmsgr.exe (PID: 2988)
    • Application launched itself

      • iexplore.exe (PID: 3440)
      • msiexec.exe (PID: 3672)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3404)
      • msiexec.exe (PID: 2292)
      • msiexec.exe (PID: 3672)
      • msiexec.exe (PID: 1528)
      • msnsearch.exe (PID: 2396)
      • mtbs.exe (PID: 604)
      • msnmsgr.exe (PID: 2988)
      • RUN_AFTER_INSTALL.exe (PID: 2964)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3404)
      • msiexec.exe (PID: 2292)
      • msiexec.exe (PID: 3672)
      • msiexec.exe (PID: 1528)
      • msnsearch.exe (PID: 2396)
      • mtbs.exe (PID: 604)
      • msnmsgr.exe (PID: 2988)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3404)
      • msiexec.exe (PID: 3672)
      • msiexec.exe (PID: 1528)
      • msiexec.exe (PID: 2292)
      • RUN_AFTER_INSTALL.exe (PID: 2964)
      • msnmsgr.exe (PID: 2988)
      • mtbs.exe (PID: 604)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3440)
      • WinRAR.exe (PID: 3872)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3872)
      • msiexec.exe (PID: 3648)
    • Creates files or folders in the user directory

      • mtbs.exe (PID: 604)
      • msiexec.exe (PID: 3672)
      • msnmsgr.exe (PID: 2988)
    • Create files in a temporary directory

      • msiexec.exe (PID: 3672)
      • msnsearch.exe (PID: 2396)
      • RUN_AFTER_INSTALL.exe (PID: 2964)
    • Reads CPU info

      • msnmsgr.exe (PID: 2988)
    • Process checks computer location settings

      • msnmsgr.exe (PID: 2988)
    • Checks proxy server information

      • msnmsgr.exe (PID: 2988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
15
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs winrar.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msnsearch.exe no specs mtbs.exe no specs mtbs.exe run_after_install.exe no specs run_after_install.exe msnmsgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
604C:\Users\admin\AppData\Local\Temp\IXP000.TMP\mtbs.exe eC:\Users\admin\AppData\Local\Temp\IXP000.TMP\mtbs.exe
msnsearch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
MSN Toolbar setup program
Exit code:
0
Version:
01.01.2607.0
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\mtbs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1432C:\Users\admin\AppData\Local\Temp\IXP000.TMP\mtbs.exe eC:\Users\admin\AppData\Local\Temp\IXP000.TMP\mtbs.exemsnsearch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
MSN Toolbar setup program
Exit code:
3221226540
Version:
01.01.2607.0
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\mtbs.exe
c:\windows\system32\ntdll.dll
1528C:\Windows\system32\MsiExec.exe -Embedding AADB4EC027228C5E86B21BF55C89F132 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1852C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2292C:\Windows\system32\MsiExec.exe -Embedding 52F5F281D0868EA4F36324038105A8CBC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2396"C:\Users\admin\AppData\Local\Temp\msnsearch.exe" /C:"mtbs.exe e"C:\Users\admin\AppData\Local\Temp\msnsearch.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Win32 Cabinet Self-Extractor
Exit code:
0
Version:
1.0.2607.0
Modules
Images
c:\users\admin\appdata\local\temp\msnsearch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2684"C:\Users\admin\AppData\Local\Temp\Rar$EXa3872.39809\RUN_AFTER_INSTALL.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3872.39809\RUN_AFTER_INSTALL.exeWinRAR.exe
User:
admin
Company:
Level Leap, Inc (levelleap.com)
Integrity Level:
MEDIUM
Description:
Patcher for Escargot
Exit code:
3221226540
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3872.39809\run_after_install.exe
c:\windows\system32\ntdll.dll
2964"C:\Users\admin\AppData\Local\Temp\Rar$EXa3872.39809\RUN_AFTER_INSTALL.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3872.39809\RUN_AFTER_INSTALL.exe
WinRAR.exe
User:
admin
Company:
Level Leap, Inc (levelleap.com)
Integrity Level:
HIGH
Description:
Patcher for Escargot
Exit code:
0
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3872.39809\run_after_install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2988"C:\Program Files\MSN Messenger\msnmsgr.exe" C:\Program Files\MSN Messenger\msnmsgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
MSN Messenger
Exit code:
0
Version:
7.5.0324
Modules
Images
c:\program files\msn messenger\msnmsgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3404"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
23 640
Read events
23 464
Write events
161
Delete events
15

Modification events

(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3440) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
29
Suspicious files
53
Text files
25
Unknown types
0

Dropped files

PID
Process
Filename
Type
3440iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:B0813C6DAA560A572A156655E3C9A55F
SHA256:206522CE32BAA63CA0982F8D0DC5687FE00B96AC3289BE5D9C0EFF07F452111E
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:B240F427A807C95DEB796853E07F2B0E
SHA256:878E9307347418926142E2F0BB0F6FE2952D5F94E645DCD4FCD7ABF08D3DE755
3440iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFFD4D44A5608D46F3.TMPbinary
MD5:63686F40C51AE15CF3984177183DC043
SHA256:8101921E4A82BAEEC6339285B6731706730E4D3AC55284CAC42D1C1756C84A23
3872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3872.37246\escargot-msn-7.5.0324-es.msi
MD5:
SHA256:
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:60FE01DF86BE2E5331B0CDBE86165686
SHA256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
3440iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{950A8CCE-830F-11EE-A826-12A9866C77DE}.datbinary
MD5:4E56894F9ED6784F0D0C7D35AE3A86D4
SHA256:D4A884016FEFBDD926DF5C011C9E207B247278C32779E0F8711E6DF80CF9049D
3440iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9D6B3FE9E6E4067193F477ABAD990106binary
MD5:F59C0E49AB735D4BEBAAA9F458F2614A
SHA256:A325523EBCF8BA33D026DC3EA6F563C940B3B0E117E887021337F12260C26D70
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\escargot-msn-7.5.0324-es[1].zipcompressed
MD5:3A7999EE8DDE2D49563315093BFD66B6
SHA256:E1585AE2FF85B629FE612A75C17837455040CDE79F2F835BB3C6FEA1BF014BED
3440iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:7A8242CCC0C8A55281A4E6185B84DCA9
SHA256:3AC5D2DA9E3E7CB0C5E9A82FE5C3FAF79B7FB703CA3E366AF4665DA54F4CFB7E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
23
DNS requests
24
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3440
iexplore.exe
GET
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
unknown
3440
iexplore.exe
GET
200
95.140.236.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?54b3b02e5c946f12
unknown
compressed
4.66 Kb
unknown
3484
iexplore.exe
GET
200
95.140.236.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?127045ce466871b6
unknown
compressed
4.66 Kb
unknown
3484
iexplore.exe
GET
200
95.140.236.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?fc0fa456ff351552
unknown
compressed
61.6 Kb
unknown
3484
iexplore.exe
GET
200
95.140.236.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?a1efb65beaf5968f
unknown
compressed
61.6 Kb
unknown
3484
iexplore.exe
GET
200
23.197.120.82:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
3484
iexplore.exe
GET
200
95.140.236.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d6bb2ad0af14907d
unknown
compressed
4.66 Kb
unknown
3440
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
3440
iexplore.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertGlobalRootG3.crl
unknown
binary
862 b
unknown
3440
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAqvpsXKY8RRQeo74ffHUxc%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3484
iexplore.exe
95.140.236.0:80
ctldl.windowsupdate.com
LLNW
US
whitelisted
3440
iexplore.exe
2.23.209.133:443
www.bing.com
Akamai International B.V.
GB
unknown
3440
iexplore.exe
95.140.236.0:80
ctldl.windowsupdate.com
LLNW
US
whitelisted
3440
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3484
iexplore.exe
23.197.120.82:80
x1.c.lencr.org
Akamai International B.V.
US
unknown
3440
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
3440
iexplore.exe
204.79.197.200:443
ieonline.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3440
iexplore.exe
2.19.246.123:443
go.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 95.140.236.0
  • 178.79.242.128
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.182
  • 2.23.209.179
  • 2.23.209.140
  • 2.23.209.187
  • 2.23.209.130
  • 2.23.209.149
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
x1.c.lencr.org
  • 23.197.120.82
whitelisted
crl3.digicert.com
  • 192.229.221.95
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
go.microsoft.com
  • 2.19.246.123
whitelisted

Threats

PID
Process
Class
Message
2988
msnmsgr.exe
Potential Corporate Privacy Violation
GPL CHAT MSN login attempt
Process
Message
mtbs.exe
1563 OS: 0x6, 0x1
mtbs.exe
*** Assertion: Unknown IE Build Format (A) ***
mtbs.exe
*** Assertion: Unknown IE Major Version ***