File name:

Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe

Full analysis: https://app.any.run/tasks/63a66237-948c-42c2-a3c4-70f3f25b3480
Verdict: Malicious activity
Analysis date: June 27, 2022, 09:50:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

961795E6F576C203ACF26756248B1061

SHA1:

2A1EBF419DE2B5B5E4B7F34BFB9C4FBEB2A060F2

SHA256:

FB7D9A5CF6AE1B52786827AB9357062EC5A7A9B49D1FAAAAEBC4B2E2B1C5F182

SSDEEP:

196608:BozgrggXBBj7QlBWIf+qivj62uKjMaaEusDCB3djS/YP0IAHIWyfuEZLNjdT1c/N:KgkgMMyXivjCKbavsDM3qqFAoW6uEZJ2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2844)
      • MsiExec.exe (PID: 3096)
      • msiexec.exe (PID: 3584)
      • Splashtop_Software_Updater.exe (PID: 3076)
      • MsiExec.exe (PID: 3524)
      • rundll32.exe (PID: 2952)
      • DrvInst.exe (PID: 2528)
      • DrvInst.exe (PID: 3468)
      • CCleaner.exe (PID: 3308)
    • Application was dropped or rewritten from another process

      • PreVerCheck.exe (PID: 1544)
      • SWXDAgent.exe (PID: 1048)
      • Splashtop_Software_Updater.exe (PID: 3076)
      • SSUService.exe (PID: 3264)
      • SWXDAgent.exe (PID: 2076)
      • SWXDAgent.exe (PID: 3392)
      • SWXDAgent.exe (PID: 1572)
      • SWXDAgent.exe (PID: 1836)
      • SWXDAgent.exe (PID: 1572)
      • SWXDAgent.exe (PID: 924)
    • Loads dropped or rewritten executable

      • SWXDAgent.exe (PID: 1048)
      • Splashtop_Software_Updater.exe (PID: 3076)
      • rundll32.exe (PID: 2952)
      • SWXDAgent.exe (PID: 2076)
      • SWXDAgent.exe (PID: 3392)
      • CCleaner.exe (PID: 3308)
      • SWXDAgent.exe (PID: 1572)
      • SWXDAgent.exe (PID: 1836)
      • SWXDAgent.exe (PID: 1572)
      • SWXDAgent.exe (PID: 924)
    • Writes to a start menu file

      • MsiExec.exe (PID: 3524)
    • Changes the autorun value in the registry

      • reg.exe (PID: 2284)
    • Loads the Task Scheduler COM API

      • CCleaner.exe (PID: 2316)
      • CCleaner.exe (PID: 3308)
    • Changes settings of System certificates

      • CCleaner.exe (PID: 3308)
    • Steals credentials from Web Browsers

      • CCleaner.exe (PID: 3308)
    • Actions looks like stealing of personal data

      • CCleaner.exe (PID: 3308)
  • SUSPICIOUS

    • Checks supported languages

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2844)
      • cmd.exe (PID: 4068)
      • PreVerCheck.exe (PID: 1544)
      • msiexec.exe (PID: 3584)
      • MsiExec.exe (PID: 3096)
      • MsiExec.exe (PID: 3524)
      • Splashtop_Software_Updater.exe (PID: 3076)
      • SWXDAgent.exe (PID: 1048)
      • cmd.exe (PID: 2344)
      • cmd.exe (PID: 2772)
      • DrvInst.exe (PID: 2528)
      • SSUService.exe (PID: 3264)
      • DrvInst.exe (PID: 3468)
      • SWXDAgent.exe (PID: 2076)
      • Skype.exe (PID: 2792)
      • Skype.exe (PID: 3892)
      • SWXDAgent.exe (PID: 3392)
      • Skype.exe (PID: 292)
      • CCleaner.exe (PID: 2316)
      • CCleaner.exe (PID: 3308)
      • Skype.exe (PID: 3528)
      • Skype.exe (PID: 3364)
      • Skype.exe (PID: 2316)
      • SWXDAgent.exe (PID: 1572)
      • SWXDAgent.exe (PID: 1836)
      • SWXDAgent.exe (PID: 924)
      • SWXDAgent.exe (PID: 1572)
      • Skype.exe (PID: 1388)
      • Skype.exe (PID: 4084)
      • Skype.exe (PID: 2020)
    • Reads the computer name

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2844)
      • PreVerCheck.exe (PID: 1544)
      • msiexec.exe (PID: 3584)
      • MsiExec.exe (PID: 3096)
      • MsiExec.exe (PID: 3524)
      • Splashtop_Software_Updater.exe (PID: 3076)
      • SSUService.exe (PID: 3264)
      • SWXDAgent.exe (PID: 1048)
      • DrvInst.exe (PID: 2528)
      • DrvInst.exe (PID: 3468)
      • Skype.exe (PID: 2792)
      • Skype.exe (PID: 3892)
      • Skype.exe (PID: 292)
      • CCleaner.exe (PID: 2316)
      • Skype.exe (PID: 3528)
      • CCleaner.exe (PID: 3308)
      • Skype.exe (PID: 2316)
      • Skype.exe (PID: 3364)
    • Drops a file with a compile date too recent

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2844)
      • MsiExec.exe (PID: 3096)
      • msiexec.exe (PID: 3584)
      • Splashtop_Software_Updater.exe (PID: 3076)
      • MsiExec.exe (PID: 3524)
      • rundll32.exe (PID: 2952)
      • DrvInst.exe (PID: 2528)
      • DrvInst.exe (PID: 3468)
      • CCleaner.exe (PID: 3308)
    • Executable content was dropped or overwritten

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2844)
      • MsiExec.exe (PID: 3096)
      • msiexec.exe (PID: 3584)
      • MsiExec.exe (PID: 3524)
      • rundll32.exe (PID: 2952)
      • DrvInst.exe (PID: 2528)
      • DrvInst.exe (PID: 3468)
      • Splashtop_Software_Updater.exe (PID: 3076)
      • CCleaner.exe (PID: 3308)
    • Starts CMD.EXE for commands execution

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2844)
      • cmd.exe (PID: 2344)
      • SWXDAgent.exe (PID: 1048)
    • Executed as Windows Service

      • vssvc.exe (PID: 3072)
      • SSUService.exe (PID: 3264)
      • taskhost.exe (PID: 2868)
      • taskhost.exe (PID: 300)
      • taskhost.exe (PID: 3680)
      • taskhost.exe (PID: 4040)
    • Reads Environment values

      • vssvc.exe (PID: 3072)
      • CCleaner.exe (PID: 2316)
      • CCleaner.exe (PID: 3308)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3584)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3584)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 3584)
      • Splashtop_Software_Updater.exe (PID: 3076)
    • Uses TASKKILL.EXE to kill process

      • MsiExec.exe (PID: 3524)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 3584)
      • DrvInst.exe (PID: 2528)
      • SSUService.exe (PID: 3264)
      • DrvInst.exe (PID: 3468)
    • Creates a software uninstall entry

      • Splashtop_Software_Updater.exe (PID: 3076)
    • Creates or modifies windows services

      • Splashtop_Software_Updater.exe (PID: 3076)
    • Creates files in the program directory

      • Splashtop_Software_Updater.exe (PID: 3076)
      • CCleaner.exe (PID: 3308)
      • SSUService.exe (PID: 3264)
    • Application launched itself

      • cmd.exe (PID: 2344)
      • Skype.exe (PID: 2792)
      • Skype.exe (PID: 292)
      • Skype.exe (PID: 3364)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 2344)
    • Removes files from Windows directory

      • msiexec.exe (PID: 3584)
      • DrvInst.exe (PID: 2528)
      • SSUService.exe (PID: 3264)
      • DrvInst.exe (PID: 3468)
      • CCleaner.exe (PID: 3308)
    • Executed via COM

      • DrvInst.exe (PID: 2528)
      • DrvInst.exe (PID: 3468)
      • DllHost.exe (PID: 3996)
    • Uses RUNDLL32.EXE to load library

      • cmd.exe (PID: 2344)
      • DrvInst.exe (PID: 2528)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2528)
      • DrvInst.exe (PID: 3468)
    • Reads CPU info

      • Skype.exe (PID: 2792)
      • CCleaner.exe (PID: 3308)
    • Creates files in the user directory

      • Skype.exe (PID: 2792)
      • Skype.exe (PID: 292)
      • CCleaner.exe (PID: 3308)
      • Skype.exe (PID: 3364)
    • Uses REG.EXE to modify Windows registry

      • Skype.exe (PID: 2792)
    • Reads the date of Windows installation

      • CCleaner.exe (PID: 3308)
    • Reads internet explorer settings

      • CCleaner.exe (PID: 3308)
    • Changes default file association

      • Skype.exe (PID: 2792)
    • Executed via Task Scheduler

      • CCleaner.exe (PID: 3308)
    • Reads Microsoft Outlook installation path

      • CCleaner.exe (PID: 3308)
      • iexplore.exe (PID: 1796)
    • Adds / modifies Windows certificates

      • CCleaner.exe (PID: 3308)
    • Reads the cookies of Google Chrome

      • CCleaner.exe (PID: 3308)
    • Reads the cookies of Mozilla Firefox

      • CCleaner.exe (PID: 3308)
    • Starts Internet Explorer

      • CCleaner.exe (PID: 3308)
    • Searches for installed software

      • CCleaner.exe (PID: 3308)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 3196)
      • vssvc.exe (PID: 3072)
      • taskkill.exe (PID: 3752)
      • sc.exe (PID: 4008)
      • sc.exe (PID: 2792)
      • sc.exe (PID: 624)
      • timeout.exe (PID: 1532)
      • rundll32.exe (PID: 2952)
      • rundll32.exe (PID: 3044)
      • taskmgr.exe (PID: 3796)
      • reg.exe (PID: 2284)
      • reg.exe (PID: 3036)
      • iexplore.exe (PID: 2540)
      • iexplore.exe (PID: 1796)
      • taskhost.exe (PID: 300)
      • taskhost.exe (PID: 2868)
      • taskhost.exe (PID: 3680)
      • taskhost.exe (PID: 4040)
      • explorer.exe (PID: 2024)
      • DllHost.exe (PID: 3996)
      • WINWORD.EXE (PID: 3152)
    • Reads the computer name

      • msiexec.exe (PID: 3196)
      • vssvc.exe (PID: 3072)
      • taskkill.exe (PID: 3752)
      • sc.exe (PID: 4008)
      • sc.exe (PID: 2792)
      • sc.exe (PID: 624)
      • rundll32.exe (PID: 2952)
      • rundll32.exe (PID: 3044)
      • taskmgr.exe (PID: 3796)
      • iexplore.exe (PID: 2540)
      • iexplore.exe (PID: 1796)
      • taskhost.exe (PID: 300)
      • taskhost.exe (PID: 2868)
      • taskhost.exe (PID: 3680)
      • taskhost.exe (PID: 4040)
      • explorer.exe (PID: 2024)
      • DllHost.exe (PID: 3996)
      • WINWORD.EXE (PID: 3152)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3584)
      • rundll32.exe (PID: 2952)
      • DrvInst.exe (PID: 2528)
      • rundll32.exe (PID: 3044)
      • DrvInst.exe (PID: 3468)
      • CCleaner.exe (PID: 3308)
      • iexplore.exe (PID: 1796)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 3584)
      • rundll32.exe (PID: 2952)
      • DrvInst.exe (PID: 2528)
      • rundll32.exe (PID: 3044)
      • DrvInst.exe (PID: 3468)
      • CCleaner.exe (PID: 3308)
      • Skype.exe (PID: 2792)
      • iexplore.exe (PID: 1796)
      • SSUService.exe (PID: 3264)
    • Application launched itself

      • msiexec.exe (PID: 3584)
      • iexplore.exe (PID: 2540)
    • Creates files in the program directory

      • msiexec.exe (PID: 3584)
      • MsiExec.exe (PID: 3524)
    • Searches for installed software

      • msiexec.exe (PID: 3584)
      • DrvInst.exe (PID: 2528)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3584)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3524)
    • Manual execution by user

      • SWXDAgent.exe (PID: 3392)
      • taskmgr.exe (PID: 3796)
      • SWXDAgent.exe (PID: 2076)
      • Skype.exe (PID: 2792)
      • CCleaner.exe (PID: 2316)
      • SWXDAgent.exe (PID: 1572)
      • SWXDAgent.exe (PID: 1836)
      • SWXDAgent.exe (PID: 924)
      • explorer.exe (PID: 2024)
      • WINWORD.EXE (PID: 3152)
      • SWXDAgent.exe (PID: 1572)
    • Reads the hosts file

      • Skype.exe (PID: 2792)
      • CCleaner.exe (PID: 3308)
    • Dropped object may contain Bitcoin addresses

      • Skype.exe (PID: 2792)
    • Changes internet zones settings

      • iexplore.exe (PID: 2540)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 2540)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 3152)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3152)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (61.2)
.ax | DirectShow filter (14.5)
.exe | Win32 EXE PECompact compressed (v2.x) (4.2)
.exe | InstallShield setup (3.1)

EXIF

EXE

ProductVersion: 1.5.8.3
ProductName: Splashtop® Wired XDisplay - Extend & Mirror
LegalCopyright: Copyright © Splashtop Inc. All Rights Reserved.
FileVersion: 1.58.9.6924
FileDescription: Splashtop® Wired XDisplay Agent
CompanyName: Splashtop Inc.
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.5.8.3
FileVersionNumber: 1.58.9.6924
Subsystem: Windows GUI
SubsystemVersion: 5
ImageVersion: -
OSVersion: 5
EntryPoint: 0x105b2
UninitializedDataSize: -
InitializedDataSize: 219136
CodeSize: 158720
LinkerVersion: 9
PEType: PE32
TimeStamp: 2020:12:14 16:13:03+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 14-Dec-2020 15:13:03
Detected languages:
  • Chinese - Taiwan
  • English - United States
Debug artifacts:
  • d:\slave\workspace\WiredXDisplay_Agent_Win\Source\wiredisplay\WiredDisplayTx\win\Release\SRUnPackFile.pdb
CompanyName: Splashtop Inc.
FileDescription: Splashtop® Wired XDisplay Agent
FileVersion: 1.58.9.6924
LegalCopyright: Copyright © Splashtop Inc. All Rights Reserved.
ProductName: Splashtop® Wired XDisplay - Extend & Mirror
ProductVersion: 1.5.8.3

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 14-Dec-2020 15:13:03
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00026B50
0x00026C00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.59923
.rdata
0x00028000
0x00008F36
0x00009000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.88966
.data
0x00031000
0x00005E98
0x00002200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.79188
.rsrc
0x00037000
0x0002A4DC
0x0002A600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.62669

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.77792
357
Latin 1 / Western European
English - United States
RT_MANIFEST
2
5.01437
67624
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
3
5.26502
38056
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
4
5.3847
16936
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
5
5.64581
9640
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
6
5.62654
6760
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
7
5.7252
4264
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
8
4.54691
1128
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
9
2.98844
376
Latin 1 / Western European
English - United States
RT_STRING
10
2.74274
180
Latin 1 / Western European
Chinese - Taiwan
RT_CURSOR

Imports

ADVAPI32.dll
COMDLG32.dll
GDI32.dll
KERNEL32.dll
OLEACC.dll (delay-loaded)
OLEAUT32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
WINSPOOL.DRV
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
117
Monitored processes
52
Malicious processes
14
Suspicious processes
9

Behavior graph

Click at the process to see the details
start splashtop_wired_xdisplay_agent_v1.5.8.3.exe cmd.exe no specs prevercheck.exe msiexec.exe no specs msiexec.exe vssvc.exe no specs msiexec.exe msiexec.exe taskkill.exe no specs splashtop_software_updater.exe ssuservice.exe swxdagent.exe no specs cmd.exe no specs cmd.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs rundll32.exe drvinst.exe rundll32.exe no specs drvinst.exe swxdagent.exe no specs taskmgr.exe no specs swxdagent.exe no specs skype.exe skype.exe reg.exe skype.exe no specs reg.exe no specs ccleaner.exe no specs ccleaner.exe skype.exe skype.exe no specs skype.exe taskhost.exe no specs iexplore.exe no specs iexplore.exe taskhost.exe no specs taskhost.exe no specs taskhost.exe no specs swxdagent.exe no specs swxdagent.exe no specs swxdagent.exe no specs swxdagent.exe no specs explorer.exe no specs Mount Point Rename no specs winword.exe no specs skype.exe no specs skype.exe no specs skype.exe no specs splashtop_wired_xdisplay_agent_v1.5.8.3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=1DF8FE76B04605E3C15B403B76182D96 --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=2 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=1DF8FE76B04605E3C15B403B76182D96 --renderer-client-id=3 --mojo-platform-channel-handle=1588 /prefetch:1C:\Program Files\Microsoft\Skype for Desktop\Skype.exeSkype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
0
Version:
8.29.0.50
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft\skype for desktop\skype.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\program files\microsoft\skype for desktop\msvcp140.dll
300"taskhost.exe"C:\Windows\system32\taskhost.exeservices.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
624sc query lci_proxywddmC:\Windows\system32\sc.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
924"C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exe" C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exeExplorer.EXE
User:
admin
Company:
Splashtop Inc.
Integrity Level:
MEDIUM
Description:
Splashtop® Wired XDisplay Agent
Exit code:
0
Version:
1.58.9.6924
Modules
Images
c:\program files\splashtop\splashtop wired xdisplay\agent\swxdagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
1048"C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exe" -dC:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exeMsiExec.exe
User:
SYSTEM
Company:
Splashtop Inc.
Integrity Level:
SYSTEM
Description:
Splashtop® Wired XDisplay Agent
Exit code:
1073807364
Version:
1.58.9.6924
Modules
Images
c:\program files\splashtop\splashtop wired xdisplay\agent\swxdagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\sechost.dll
1388"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=EE2C34B55CED8911CAFFA642BF716313 --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=1 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=EE2C34B55CED8911CAFFA642BF716313 --renderer-client-id=6 --mojo-platform-channel-handle=2868 /prefetch:1C:\Program Files\Microsoft\Skype for Desktop\Skype.exeSkype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
3221226091
Version:
8.29.0.50
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft\skype for desktop\skype.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\skype for desktop\node.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\microsoft\skype for desktop\vcruntime140.dll
1532timeout /t 2 /nobreakC:\Windows\system32\timeout.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
1544PreVerCheck.exeC:\Users\admin\AppData\Local\Temp\unpack\PreVerCheck.exe
cmd.exe
User:
admin
Company:
Splashtop Inc.
Integrity Level:
HIGH
Description:
Splashtop® Wired XDisplay Agent Installer
Exit code:
0
Version:
1.58.9.6924
Modules
Images
c:\users\admin\appdata\local\temp\unpack\prevercheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1572"C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exe" C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exeExplorer.EXE
User:
admin
Company:
Splashtop Inc.
Integrity Level:
MEDIUM
Description:
Splashtop® Wired XDisplay Agent
Exit code:
0
Version:
1.58.9.6924
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\splashtop\splashtop wired xdisplay\agent\swxdagent.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1572"C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exe" -hC:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exeExplorer.EXE
User:
admin
Company:
Splashtop Inc.
Integrity Level:
MEDIUM
Description:
Splashtop® Wired XDisplay Agent
Exit code:
0
Version:
1.58.9.6924
Modules
Images
c:\program files\splashtop\splashtop wired xdisplay\agent\swxdagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
Total events
66 277
Read events
64 854
Write events
1 189
Delete events
234

Modification events

(PID) Process:(2844) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2844) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2844) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2844) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3584) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
400000000000000044C11B560B8AD801000E0000B8020000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3584) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
400000000000000044C11B560B8AD801000E0000B8020000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3584) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
69
(PID) Process:(3584) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
400000000000000038D16C560B8AD801000E0000B8020000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3584) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
400000000000000038D16C560B8AD801000E00006C030000E803000001000000000000000000000042870A2125C8A24E9507390F0D8862180000000000000000
(PID) Process:(3072) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000541F7B560B8AD801000C00007C0F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
78
Suspicious files
129
Text files
68
Unknown types
61

Dropped files

PID
Process
Filename
Type
2844Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack\setup.msi
MD5:
SHA256:
3584msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3584msiexec.exeC:\Windows\Installer\fceef.msi
MD5:
SHA256:
3584msiexec.exeC:\Windows\Installer\MSID559.tmp
MD5:
SHA256:
2844Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack.logini
MD5:
SHA256:
3584msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
3584msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{210a8742-c825-4ea2-9507-390f0d886218}_OnDiskSnapshotPropbinary
MD5:
SHA256:
1544PreVerCheck.exeC:\Users\admin\AppData\Local\Temp\PreVerC.logini
MD5:
SHA256:
3584msiexec.exeC:\Windows\Installer\fcef1.ipibinary
MD5:
SHA256:
3584msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF71F80208BACA7BE8.TMPgmc
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
55
DNS requests
39
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3308
CCleaner.exe
GET
301
104.90.109.251:80
http://www.ccleaner.com/auto?a=0&p=cc&v=5.74.8198&l=1033&lk=&mk=V4K3-4CYC-FETV-5ACD-MEU8-3V4M-VMIH-FBZ6-7HA8&o=6.1W3&au=0&mx=97B7721C4994E2556FF6A439510F665DB45337A341A47E15F4997584423BF714&gd=19ce970b-f6c0-4a09-bae4-274b971730e0
NL
whitelisted
3308
CCleaner.exe
GET
200
104.90.110.183:80
http://license.piriform.com/verify/?p=ccpro&c=cc&cv=5.74.8198&l=1033&lk=CJ9T-J7CU-SPNV-GWMB-WBEC&mk=V4K3-4CYC-FETV-5ACD-MEU8-3V4M-VMIH-FBZ6-7HA8&mx=97B7721C4994E2556FF6A439510F665DB45337A341A47E15F4997584423BF714&gd=19ce970b-f6c0-4a09-bae4-274b971730e0
NL
text
16 b
whitelisted
3308
CCleaner.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
3308
CCleaner.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEAT%2FrubUb6nOEpcsoEFY3SI%3D
US
der
471 b
whitelisted
3308
CCleaner.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D
US
der
471 b
whitelisted
3264
SSUService.exe
POST
107.22.247.100:80
http://ds1.devicevm.com/
US
suspicious
3308
CCleaner.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
US
der
471 b
whitelisted
3308
CCleaner.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
1796
iexplore.exe
GET
200
143.204.101.195:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
1796
iexplore.exe
GET
200
143.204.101.42:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3308
CCleaner.exe
5.62.48.53:443
ipm-provider.ff.avast.com
AVAST Software s.r.o.
US
suspicious
3308
CCleaner.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3264
SSUService.exe
44.194.169.0:80
sn.splashtop.com
University of California, San Diego
US
unknown
3264
SSUService.exe
44.194.169.0:443
sn.splashtop.com
University of California, San Diego
US
unknown
2792
Skype.exe
13.107.43.16:443
a.config.skype.com
Microsoft Corporation
US
whitelisted
2792
Skype.exe
52.174.193.75:443
get.skype.com
Microsoft Corporation
NL
whitelisted
2792
Skype.exe
92.122.144.83:443
download.skype.com
Akamai International B.V.
unknown
2792
Skype.exe
20.189.173.11:443
pipe.skype.com
Microsoft Corporation
US
suspicious
3308
CCleaner.exe
92.123.225.56:80
ncc.avast.com
Akamai International B.V.
suspicious
3308
CCleaner.exe
5.62.40.230:443
analytics.ff.avast.com
AVAST Software s.r.o.
DE
unknown

DNS requests

Domain
IP
Reputation
sn.splashtop.com
  • 44.194.169.0
  • 52.204.148.77
  • 52.200.149.109
unknown
get.skype.com
  • 52.174.193.75
whitelisted
a.config.skype.com
  • 13.107.43.16
whitelisted
pipe.skype.com
  • 20.189.173.11
whitelisted
download.skype.com
  • 92.122.144.83
whitelisted
ncc.avast.com
  • 92.123.225.56
  • 92.123.225.75
whitelisted
analytics.ff.avast.com
  • 5.62.40.230
  • 5.62.40.215
whitelisted
www.ccleaner.com
  • 104.90.109.251
whitelisted
shepherd.ff.avast.com
  • 5.62.40.202
  • 5.62.48.203
whitelisted
ipm-provider.ff.avast.com
  • 5.62.48.53
  • 5.62.40.17
  • 5.62.45.38
  • 5.62.48.55
  • 5.62.40.36
  • 5.62.38.45
  • 69.94.68.222
  • 69.94.76.55
  • 5.62.40.19
  • 5.62.40.37
  • 5.62.42.30
  • 5.62.38.44
whitelisted

Threats

PID
Process
Class
Message
Misc activity
ET INFO Splashtop Domain in DNS Lookup (splashtop .com)
3264
SSUService.exe
Misc activity
ET INFO Splashtop Domain (splashtop .com) in TLS SNI
3308
CCleaner.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
Misc activity
ET INFO Splashtop Domain in DNS Lookup (splashtop .com)
3264
SSUService.exe
Misc activity
ET INFO Splashtop Domain (splashtop .com) in TLS SNI
Misc activity
ET INFO Splashtop Domain in DNS Lookup (splashtop .com)
3264
SSUService.exe
Misc activity
ET INFO Splashtop Domain (splashtop .com) in TLS SNI
Process
Message
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUtility::OSInfo] OS 6.1(7601) Service Pack 1 x64:0 Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUnPack::FindHeader] Name:C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUnPack::FindHeader] Sign Size:6096 Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUnPack::FindHeader] Header offset:378880 Err:183
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUnPack::UnPackFiles] FreeSpace:234466938880 FileSize:11297280 Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUnPack::UnPackFiles] (1/4)UnPack file name:C:\Users\admin\AppData\Local\Temp\unpack\setup.msi (11297280) Err:2
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUnPack::UnPackFiles] UnPack count:1 len:11297280 File:(null) Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUnPack::UnPackFiles] FreeSpace:234455638016 FileSize:15 Err:183
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUnPack::UnPackFiles] (2/4)UnPack file name:C:\Users\admin\AppData\Local\Temp\unpack\run.bat (15) Err:122
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2844]2022-06-27 10:50:29 [CUnPack::UnPackFiles] UnPack count:2 len:15 File:(null) Err:0