File name:

SaraSetup.exe

Full analysis: https://app.any.run/tasks/7f676e2b-04d0-4366-bab3-05b0d5982dcb
Verdict: Malicious activity
Analysis date: September 05, 2024, 09:03:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

0036F94BC842FB3B335A4D24890E4702

SHA1:

ECEB9102AFBB3C15C47ABD3E86AFF7F3BF570F62

SHA256:

FB8E5F1C5CD5D26D7C325B553017CE8E4CBF4F4C792DC9EFEB1A07FA1F63F6E6

SSDEEP:

3072:8Pt3oYOBf73zAuN0EBtE8gTL6tvIiw9K8gj/r1WmKH/ocH7j/T8rS6XUkN//:8poYOBj0xK8gj/8j/T8nEqX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Searches for installed software

      • SaraSetup.exe (PID: 6156)
      • Microsoft.Sara.exe (PID: 7076)
    • Process drops legitimate windows executable

      • SaraSetup.exe (PID: 6156)
    • Executable content was dropped or overwritten

      • SaraSetup.exe (PID: 6156)
    • The process creates files with name similar to system file names

      • SaraSetup.exe (PID: 6156)
    • The process drops C-runtime libraries

      • SaraSetup.exe (PID: 6156)
    • Creates a software uninstall entry

      • SaraSetup.exe (PID: 6156)
      • Microsoft.Sara.exe (PID: 7076)
    • Reads Microsoft Outlook installation path

      • Microsoft.Sara.exe (PID: 7076)
  • INFO

    • Reads the machine GUID from the registry

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Reads the computer name

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Checks supported languages

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Disables trace logs

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Creates files or folders in the user directory

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
    • Reads the software policy settings

      • SaraSetup.exe (PID: 6156)
      • slui.exe (PID: 2524)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
      • slui.exe (PID: 5344)
    • Checks proxy server information

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
      • Microsoft.Sara.exe (PID: 7076)
      • slui.exe (PID: 5344)
    • Sends debugging messages

      • SaraSetup.exe (PID: 6156)
      • Microsoft.Sara.exe (PID: 7076)
    • Process checks whether UAC notifications are on

      • SaraSetup.exe (PID: 6156)
    • The process uses the downloaded file

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
    • Create files in a temporary directory

      • SaraSetup.exe (PID: 6156)
      • dfsvc.exe (PID: 5944)
    • Process checks computer location settings

      • SaraSetup.exe (PID: 6156)
    • Reads Environment values

      • dfsvc.exe (PID: 5944)
    • Dropped object may contain TOR URL's

      • SaraSetup.exe (PID: 6156)
    • Creates files in the program directory

      • Microsoft.Sara.exe (PID: 7076)
    • Reads Microsoft Office registry keys

      • Microsoft.Sara.exe (PID: 7076)
    • Reads CPU info

      • Microsoft.Sara.exe (PID: 7076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2089:01:22 12:34:06+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 166400
InitializedDataSize: 72704
UninitializedDataSize: -
EntryPoint: 0x2a98e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 17.1.2176.0
ProductVersionNumber: 17.1.2176.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Microsoft Corporation.
FileDescription: Microsoft Support and Recovery Assistant Setup
InternalName: SaraSetup.exe
LegalCopyright: Copyright © 1995-2015 Microsoft Corporation.
LegalTrademarks: Microsoft® is a registered trademark of Microsoft Corporation.
OriginalFileName: SaraSetup.exe
ProductName: Microsoft® Exchange
FileVersion: 17.01.2176.000
ProductVersion: 17.01.2176.000
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start sarasetup.exe sppextcomobj.exe no specs slui.exe slui.exe rundll32.exe no specs dfsvc.exe microsoft.sara.exe

Process information

PID
CMD
Path
Indicators
Parent process
2524"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4160"C:\WINDOWS\system32\rundll32.exe" dfshim.dll, ShOpenVerbApplication https://outlookdiagnostics.azureedge.net/sarafiles/Microsoft.Sara.Prod.applicationC:\Windows\SysWOW64\rundll32.exeSaraSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5344C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5944"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
ClickOnce
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\dfsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6156"C:\Users\admin\AppData\Local\Temp\SaraSetup.exe" C:\Users\admin\AppData\Local\Temp\SaraSetup.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation.
Integrity Level:
MEDIUM
Description:
Microsoft Support and Recovery Assistant Setup
Exit code:
0
Version:
17.01.2176.000
Modules
Images
c:\users\admin\appdata\local\temp\sarasetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6712C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7076"C:\Users\admin\AppData\Local\Apps\2.0\NCRC8HRD.Y62\3YDQN9XW.3RK\micr..tion_5661bd3e342e4e9f_0011.0001_b83c144db5a74952\Microsoft.Sara.exe"C:\Users\admin\AppData\Local\Apps\2.0\NCRC8HRD.Y62\3YDQN9XW.3RK\micr..tion_5661bd3e342e4e9f_0011.0001_b83c144db5a74952\Microsoft.Sara.exe
dfsvc.exe
User:
admin
Company:
Microsoft Corporation.
Integrity Level:
MEDIUM
Description:
Microsoft Support and Recovery Assistant
Version:
17.01.2176.000
Modules
Images
c:\users\admin\appdata\local\apps\2.0\ncrc8hrd.y62\3ydqn9xw.3rk\micr..tion_5661bd3e342e4e9f_0011.0001_b83c144db5a74952\microsoft.sara.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
Total events
15 235
Read events
11 825
Write events
2 840
Delete events
570

Modification events

(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:writeName:ComponentStore_RandomString
Value:
9CB6EZR5ZLVAEB0CHBRG2PG1
(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:delete valueName:ComponentStore_RandomString
Value:
9CB6EZR5ZLVAEB0CHBRG2PG1
(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:delete keyName:(default)
Value:
(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:writeName:ComponentStore_RandomString
Value:
NCRC8HRDY623YDQN9XW3RKDE
(PID) Process:(6156) SaraSetup.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\StateManager
Operation:writeName:StateStore_RandomString
Value:
8NVTJGH854VX52JXV1Q38C1E
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6156) SaraSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\SaraSetup_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
Executable files
394
Suspicious files
191
Text files
504
Unknown types
0

Dropped files

PID
Process
Filename
Type
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\roiscan.config.xmlxml
MD5:7936522251318CDCFFDB9A75C879FF34
SHA256:D152B95508CF08BEB65A6C85E5B779CAFCFB59C778411B0DBD431828C09428A9
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\SaraEULA.txttext
MD5:A811F7A46C12ED29C5713A64F528569A
SHA256:30AFE28070DD647EFB545549CBDDCBBF9D40C7424BC93FECC8E7AE51A668D7EB
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\sara2.icoimage
MD5:64ABE480FD183A30B203DAAC7A523821
SHA256:38FE914C14F96C6BECB22203D722E15036A49F78E085F339236BC7E18D6D3A06
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\Microsoft.IdentityModel.Clients.ActiveDirectory.WindowsForms.dllexecutable
MD5:DAD75B06FCDBA45BC622BAF0582E806A
SHA256:C24A11C0E4AE4BD202DBC2002CBA4E29B18A5008063DCE2ABC922B7078E7519B
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\tools\x64\mrmapi.exeexecutable
MD5:2B09ABEFDC84D46D10C2A83B0870F3D4
SHA256:973DEE4EE73FDF7BC5815D7EDF3DDEE8E0C40B259BC1DCDE603B0BB3AE732CAA
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\excel.crashes.config.xmlxml
MD5:18DE8EB6DDFDCADF929D0CEDD963BA6D
SHA256:D8117328E9020E3623AE144BAB81412B189C72D0A8C28BAFDFE8D49933B2FE65
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\offcat.config.xmlxml
MD5:146D0C42C4F6111DC20CCE076B7F5DB4
SHA256:FD3D83ABB166819AD9EA49350456BC39A191F7C58F4B97C94B309DD2C71D2587
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\word.crashes.config.xmlxml
MD5:0E0B4AD7DA7EABB31E7F4C2820D74AFE
SHA256:F7FD0E19100512CEFAA8338FD9ABD94524E19B8459A52478A830B905EBBF326F
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\lync.crashes.config.xmlxml
MD5:31F51B3B4A5B4E0BE1C72260FC9FC7F3
SHA256:DB93480626C8450D7897AA31243617E59ECF04FA52C8584C475342D28E9AF8FB
6156SaraSetup.exeC:\Users\admin\AppData\Local\Temp\Deployment\29EGH49V.B65\Y4H2P5KT.TKM\en\onedrive.crashes.config.xmlxml
MD5:2831DFE42511411BF428A37D015A8C18
SHA256:5FDEA805FAB0A00713593F930DF7085EC3CF0B6D07A731985D6294279D99FFDD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
34
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6876
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1404
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3160
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3160
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
6876
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2400
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6156
SaraSetup.exe
152.199.19.160:443
outlookdiagnostics.azureedge.net
EDGECAST
US
whitelisted
6876
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3260
svchost.exe
20.7.2.167:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1404
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1404
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 216.58.206.46
whitelisted
outlookdiagnostics.azureedge.net
  • 152.199.19.160
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 20.7.2.167
whitelisted
login.live.com
  • 20.190.160.14
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.20
  • 20.190.160.22
  • 40.126.32.74
  • 40.126.32.134
  • 40.126.32.72
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 40.68.123.157
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
Process
Message
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
SaraSetup.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230