File name:

SaraSetup.exe

Full analysis: https://app.any.run/tasks/7f676e2b-04d0-4366-bab3-05b0d5982dcb
Verdict: Malicious activity
Analysis date: September 05, 2024, 09:03:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

0036F94BC842FB3B335A4D24890E4702

SHA1:

ECEB9102AFBB3C15C47ABD3E86AFF7F3BF570F62

SHA256:

FB8E5F1C5CD5D26D7C325B553017CE8E4CBF4F4C792DC9EFEB1A07FA1F63F6E6

SSDEEP:

3072:8Pt3oYOBf73zAuN0EBtE8gTL6tvIiw9K8gj/r1WmKH/ocH7j/T8rS6XUkN//:8poYOBj0xK8gj/8j/T8nEqX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • SaraSetup.exe (PID: 6156)
    • Reads security settings of Internet Explorer

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • The process creates files with name similar to system file names

      • SaraSetup.exe (PID: 6156)
    • Creates a software uninstall entry

      • SaraSetup.exe (PID: 6156)
      • Microsoft.Sara.exe (PID: 7076)
    • Executable content was dropped or overwritten

      • SaraSetup.exe (PID: 6156)
    • The process drops C-runtime libraries

      • SaraSetup.exe (PID: 6156)
    • Searches for installed software

      • Microsoft.Sara.exe (PID: 7076)
      • SaraSetup.exe (PID: 6156)
    • Reads Microsoft Outlook installation path

      • Microsoft.Sara.exe (PID: 7076)
  • INFO

    • Checks supported languages

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Reads the machine GUID from the registry

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Checks proxy server information

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
      • slui.exe (PID: 5344)
    • Creates files or folders in the user directory

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Disables trace logs

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • The process uses the downloaded file

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
    • Create files in a temporary directory

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
    • Reads the computer name

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Sends debugging messages

      • SaraSetup.exe (PID: 6156)
      • Microsoft.Sara.exe (PID: 7076)
    • Dropped object may contain TOR URL's

      • SaraSetup.exe (PID: 6156)
    • Reads the software policy settings

      • SaraSetup.exe (PID: 6156)
      • slui.exe (PID: 2524)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
      • slui.exe (PID: 5344)
    • Process checks computer location settings

      • SaraSetup.exe (PID: 6156)
    • Reads Environment values

      • dfsvc.exe (PID: 5944)
    • Creates files in the program directory

      • Microsoft.Sara.exe (PID: 7076)
    • Reads Microsoft Office registry keys

      • Microsoft.Sara.exe (PID: 7076)
    • Process checks whether UAC notifications are on

      • SaraSetup.exe (PID: 6156)
    • Reads CPU info

      • Microsoft.Sara.exe (PID: 7076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2089:01:22 12:34:06+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 166400
InitializedDataSize: 72704
UninitializedDataSize: -
EntryPoint: 0x2a98e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 17.1.2176.0
ProductVersionNumber: 17.1.2176.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Microsoft Corporation.
FileDescription: Microsoft Support and Recovery Assistant Setup
InternalName: SaraSetup.exe
LegalCopyright: Copyright © 1995-2015 Microsoft Corporation.
LegalTrademarks: Microsoft® is a registered trademark of Microsoft Corporation.
OriginalFileName: SaraSetup.exe
ProductName: Microsoft® Exchange
FileVersion: 17.01.2176.000
ProductVersion: 17.01.2176.000
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start sarasetup.exe sppextcomobj.exe no specs slui.exe slui.exe rundll32.exe no specs dfsvc.exe microsoft.sara.exe

Process information

PID
CMD
Path
Indicators
Parent process
2524"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4160"C:\WINDOWS\system32\rundll32.exe" dfshim.dll, ShOpenVerbApplication https://outlookdiagnostics.azureedge.net/sarafiles/Microsoft.Sara.Prod.applicationC:\Windows\SysWOW64\rundll32.exeSaraSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5344C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5944"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
ClickOnce
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\dfsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6156"C:\Users\admin\AppData\Local\Temp\SaraSetup.exe" C:\Users\admin\AppData\Local\Temp\SaraSetup.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation.
Integrity Level:
MEDIUM
Description:
Microsoft Support and Recovery Assistant Setup
Exit code:
0
Version:
17.01.2176.000
Modules
Images
c:\users\admin\appdata\local\temp\sarasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6712C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7076"C:\Users\admin\AppData\Local\Apps\2.0\NCRC8HRD.Y62\3YDQN9XW.3RK\micr..tion_5661bd3e342e4e9f_0011.0001_b83c144db5a74952\Microsoft.Sara.exe"C:\Users\admin\AppData\Local\Apps\2.0\NCRC8HRD.Y62\3YDQN9XW.3RK\micr..tion_5661bd3e342e4e9f_0011.0001_b83c144db5a74952\Microsoft.Sara.exe
dfsvc.exe
User:
admin
Company:
Microsoft Corporation.
Integrity Level:
MEDIUM
Description:
Microsoft Support and Recovery Assistant
Version:
17.01.2176.000
Modules
Images
c:\users\admin\appdata\local\apps\2.0\ncrc8hrd.y62\3ydqn9xw.3rk\micr..tion_5661bd3e342e4e9f_0011.0001_b83c144db5a74952\microsoft.sara.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
Total events
15 235
Read events
11 825
Write events
2 840
Delete events
570

Modification events

(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:writeName:ComponentStore_RandomString
Value:
9CB6EZR5ZLVAEB0CHBRG2PG1
(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:delete valueName:ComponentStore_RandomString
Value:
9CB6EZR5ZLVAEB0CHBRG2PG1
(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:delete keyName:(default)
Value:
(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:writeName:ComponentStore_RandomString
Value:
NCRC8HRDY623YDQN9XW3RKDE
(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\StateManager
Operation:writeName:StateStore_RandomString
Value:
8NVTJGH854VX52JXV1Q38C1E
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
Executable files
394
Suspicious files
191
Text files
504
Unknown types
0

Dropped files

PID
Process
Filename
Type
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\Microsoft.IdentityModel.Clients.ActiveDirectory.WindowsForms.dllexecutable
MD5:DAD75B06FCDBA45BC622BAF0582E806A
SHA256:C24A11C0E4AE4BD202DBC2002CBA4E29B18A5008063DCE2ABC922B7078E7519B
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\sara2.icoimage
MD5:64ABE480FD183A30B203DAAC7A523821
SHA256:38FE914C14F96C6BECB22203D722E15036A49F78E085F339236BC7E18D6D3A06
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\offcat.config.xmlxml
MD5:146D0C42C4F6111DC20CCE076B7F5DB4
SHA256:FD3D83ABB166819AD9EA49350456BC39A191F7C58F4B97C94B309DD2C71D2587
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\tools\x64\mrmapi.exeexecutable
MD5:2B09ABEFDC84D46D10C2A83B0870F3D4
SHA256:973DEE4EE73FDF7BC5815D7EDF3DDEE8E0C40B259BC1DCDE603B0BB3AE732CAA
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\infopath.crashes.config.xmlxml
MD5:07AD642C4DBB80E88A5B73AD9423B50D
SHA256:D31FEA7660E2C1CEA0CFB98D99DA18F0870B7862931A0E1D30122E66386C2608
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\publisher.crashes.config.xmlxml
MD5:6A46AEA92080C7190A38D54FC59C5469
SHA256:10182233F5D8F3E808F3C9170B093BEDD718D6BEDA28F8EA242A84F20706B599
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\AZ0QEXEM.1N0\LPXM8T20.QJZ.applicationxml
MD5:D847EEC6D36F7452F72CF2FDA4E151CD
SHA256:368D959413BC98005631D741A55352A0461C60A725EDD803B6850AFF96A6E185
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\common.config.xmlxml
MD5:E60B202BDAC4BA165D08A32534738E88
SHA256:F646A88D1FE5A3AB759F67E8363C5F5B7DF17B7EED8907CBC472F567F6E7D133
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\word.crashes.config.xmlxml
MD5:0E0B4AD7DA7EABB31E7F4C2820D74AFE
SHA256:F7FD0E19100512CEFAA8338FD9ABD94524E19B8459A52478A830B905EBBF326F
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\onedrive.crashes.config.xmlxml
MD5:2831DFE42511411BF428A37D015A8C18
SHA256:5FDEA805FAB0A00713593F930DF7085EC3CF0B6D07A731985D6294279D99FFDD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
34
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3160
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3160
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1404
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6876
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
6876
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2400
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6156
SaraSetup.exe
152.199.19.160:443
outlookdiagnostics.azureedge.net
EDGECAST
US
whitelisted
6876
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3260
svchost.exe
20.7.2.167:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1404
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1404
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 216.58.206.46
whitelisted
outlookdiagnostics.azureedge.net
  • 152.199.19.160
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 20.7.2.167
whitelisted
login.live.com
  • 20.190.160.14
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.20
  • 20.190.160.22
  • 40.126.32.74
  • 40.126.32.134
  • 40.126.32.72
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 40.68.123.157
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
Process
Message
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230