| File name: | PowerGUI.3.8.0.129.msi |
| Full analysis: | https://app.any.run/tasks/46eae25c-adc8-4757-99cd-8d26cd9e6050 |
| Verdict: | Malicious activity |
| Analysis date: | April 02, 2019, 16:34:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Name of Creating Application: Wise for Windows Installer - Professional Edition Standalone, Last Saved Time/Date: Tue Oct 29 14:25:33 2013, Create Time/Date: Tue Oct 29 14:25:33 2013, Last Printed: Tue Oct 29 14:25:33 2013, Title: Quest PowerGUI 3.8, Subject: Quest PowerGUI 3.8, Author: Quest Software, Inc., Comments: The Installation database contains the logic and data required to install Quest PowerGUI 3.8 ., Template: ;1033, Last Saved By: Builder, Revision Number: {FBF9163D-0B76-4C43-A553-37631E8358E0}, Number of Pages: 200, Number of Words: 2 |
| MD5: | 59E342F9267013E568631BD2E2D30B0C |
| SHA1: | 4C8BE00FF6DD070842EF9CCAA6CFD288BE248AC2 |
| SHA256: | F3570BD7DBE4B2D5B2FC41FF1D1D3E5B8173229BB69116678405024E0CEA6EEA |
| SSDEEP: | 393216:AdvNl5YoNVmmGuNJWxQgg5e3WPuBjxPffAd/twU:U1lKAmmlNJ6Jg5gWGxRff |
| .msi | | | Microsoft Windows Installer (81.9) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (9.2) |
| .msp | | | Windows Installer Patch (7.6) |
| .msi | | | Microsoft Installer (100) |
| Software: | Wise for Windows Installer - Professional Edition Standalone |
|---|---|
| ModifyDate: | 2013:10:29 14:25:33 |
| CreateDate: | 2013:10:29 14:25:33 |
| LastPrinted: | 2013:10:29 14:25:33 |
| Title: | Quest PowerGUI? 3.8 |
| Subject: | Quest PowerGUI? 3.8 |
| Author: | Quest Software, Inc. |
| Keywords: | - |
| Comments: | The Installation database contains the logic and data required to install Quest PowerGUI? 3.8 . |
| Template: | ;1033 |
| LastModifiedBy: | Builder |
| RevisionNumber: | {FBF9163D-0B76-4C43-A553-37631E8358E0} |
| Pages: | 200 |
| Words: | 2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 692 | "C:\Users\admin\AppData\Local\Temp\SetupHelper3.8.0.129.exe" path="C:\Program Files\PowerGUI" phase=enumAeDePhaseDo1 action=esaInstall msi="C:\Users\admin\AppData\Local\Temp" uilevel=5 method=InstallAction | C:\Users\admin\AppData\Local\Temp\SetupHelper3.8.0.129.exe | — | RPC1622.tmp | |||||||||||
User: admin Company: Quest Software Integrity Level: MEDIUM Description: SetupHelper Exit code: 0 Version: 3.8.0.129 Modules
| |||||||||||||||
| 1344 | C:\Windows\system32\MsiExec.exe -Embedding A1CF91A0B60F275E1531B18E517DD9C0 | C:\Windows\system32\MsiExec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1380 | "C:\Users\admin\AppData\Local\Temp\SetupHelperLS3.8.0.129.exe" path="C:\Program Files\PowerGUI" phase=enumAeDePhasePrepare action=esaInstall msi="C:\Users\admin\AppData\Local\Temp" uilevel=5 method=InstallActionLocalSystem | C:\Users\admin\AppData\Local\Temp\SetupHelperLS3.8.0.129.exe | — | MsiExec.exe | |||||||||||
User: admin Company: Quest Software Integrity Level: MEDIUM Description: SetupHelper Exit code: 0 Version: 3.8.0.129 Modules
| |||||||||||||||
| 1452 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 22c -InterruptEvent 0 -NGENProcess 19c -Pipe 228 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 1524 | "C:\Users\admin\AppData\Local\Temp\SetupHelper3.8.0.129.exe" path="C:\Program Files\PowerGUI" phase=enumAeDePhaseDo2 action=esaInstall msi="C:\Users\admin\AppData\Local\Temp" uilevel=5 method=InstallAction | C:\Users\admin\AppData\Local\Temp\SetupHelper3.8.0.129.exe | — | RPC1622.tmp | |||||||||||
User: admin Company: Quest Software Integrity Level: MEDIUM Description: SetupHelper Exit code: 0 Version: 3.8.0.129 Modules
| |||||||||||||||
| 1640 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1e4 -InterruptEvent 0 -NGENProcess 19c -Pipe 1b0 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | ngen.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 1668 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1e4 -InterruptEvent 0 -NGENProcess 1bc -Pipe 1cc -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | ngen.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 1924 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1e4 -InterruptEvent 0 -NGENProcess 1d4 -Pipe 1b8 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | ngen.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 2068 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 108 -InterruptEvent 0 -NGENProcess f8 -Pipe 104 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 2184 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 250 -InterruptEvent 0 -NGENProcess 244 -Pipe 23c -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| (PID) Process: | (3984) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3580) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000B299D11472E9D401FC0D00004C0C0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3580) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000B299D11472E9D401FC0D00004C0C0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3580) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 20 | |||
| (PID) Process: | (3580) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000920A441572E9D401FC0D00004C0C0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3580) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000EC6C461572E9D401FC0D0000A8020000E803000001000000000000000000000030E8A1E836047842A567510C44EA8F200000000000000000 | |||
| (PID) Process: | (2604) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000CAA6601572E9D4012C0A0000B8050000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2604) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000CAA6601572E9D4012C0A000014030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2604) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000CAA6601572E9D4012C0A000030020000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2604) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000CAA6601572E9D4012C0A000098050000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI88E2.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI89BE.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI89EE.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI8A1E.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI8A6D.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI8ACC.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI8ADC.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI8AED.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI9B69.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI9F71.tmp | — | |
MD5:— | SHA256:— | |||
Process | Message |
|---|---|
MsiExec.exe | GetUserDefaultUILanguage=1033. |
MsiExec.exe | Japanese language detected. Changing ProductName... |
MsiExec.exe | Checking system configuration: |
MsiExec.exe | Getting OS version information... |
MsiExec.exe | VER_NT_ADVANSED_SERVER=0 |
MsiExec.exe | VER_NT_WORKSTATION=1 |
MsiExec.exe | VER_NT_DOMAIN_CONTROLLER=0 |
MsiExec.exe | VER_NT_SERVER=0 |
MsiExec.exe | VER_SUITE_SMALLBUSINESS=0 |
MsiExec.exe | VER_SUITE_ENTERPRISE=0 |