Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
MSDisplay_MultiDev_v1.0.0.18.0.exe

Overview

General Information

Sample Name:MSDisplay_MultiDev_v1.0.0.18.0.exe
Analysis ID:838207
MD5:f505cbcab0670a376c866de177a5c097
SHA1:18ded789bc554fda5941aa2707df9a78de44c7c5
SHA256:7be04791df7cc79fc8427098bf9e3c11206e54d2d613d470e4b4d5855451e816
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Changes security center settings (notifications, updates, antivirus, firewall)
Obfuscated command line found
Creates an undocumented autostart registry key
Uses 32bit PE files
Creates files inside the driver directory
Queries the volume information (name, serial number etc) of a device
Drops certificate files (DER)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Deletes files inside the Windows folder
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Creates files inside the system directory
PE file contains sections with non-standard names
Stores files to the Windows start menu directory
Found dropped PE file which has not been started or loaded
Enables driver privileges
Adds / modifies Windows certificates
Drops PE files
Contains capabilities to detect virtual machines
Enables security privileges
Spawns drivers
Creates or modifies windows services
Queries disk information (often used to detect virtual machines)

Classification

  • System is w10x64_ra
  • svchost.exe (PID: 6596 cmdline: C:\Windows\System32\svchost.exe -k NetworkService -p MD5: 9520A99E77D6196D0D09833146424113)
  • SgrmBroker.exe (PID: 6636 cmdline: C:\Windows\system32\SgrmBroker.exe MD5: C51AA0BB954EA45E85572E6CC29BA6F4)
  • svchost.exe (PID: 6672 cmdline: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc MD5: 9520A99E77D6196D0D09833146424113)
  • MSDisplay_MultiDev_v1.0.0.18.0.exe (PID: 6848 cmdline: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe MD5: F505CBCAB0670A376C866DE177A5C097)
    • MSDisplay_MultiDev_v1.0.0.18.0.tmp (PID: 6880 cmdline: "C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp" /SL5="$40132,2556185,806912,C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe" MD5: 7EC9CFAB450831249D70152183B3E844)
      • devcon.exe (PID: 7148 cmdline: "C:\Program Files\MS USB Display\tool\x64\devcon.exe" dp_add "C:\Program Files\MS USB Display\lib_usb\MSUSBDisplay.inf" USB\VID_534D&PID_6021&MI_03 MD5: 8C7D36AD908F5F1A5E39F95AC92581F5)
        • conhost.exe (PID: 7164 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • devcon.exe (PID: 1032 cmdline: "C:\Program Files\MS USB Display\tool\x64\devcon.exe" install "C:\Program Files\MS USB Display\idd\indirectdisplaybus\indirectdisplaybus.inf" root\IndirectDisplayBus MD5: 8C7D36AD908F5F1A5E39F95AC92581F5)
        • conhost.exe (PID: 4700 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • devcon.exe (PID: 1868 cmdline: "C:\Program Files\MS USB Display\tool\x64\devcon.exe" update "C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\indirectdisplaydriver0.inf" MS\IddBus MD5: 8C7D36AD908F5F1A5E39F95AC92581F5)
        • conhost.exe (PID: 1984 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • devcon.exe (PID: 6920 cmdline: "C:\Program Files\MS USB Display\tool\x64\devcon.exe" update "C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\indirectdisplaydriver1.inf" MS\IddBus1 MD5: 8C7D36AD908F5F1A5E39F95AC92581F5)
        • conhost.exe (PID: 1288 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • devcon.exe (PID: 2568 cmdline: "C:\Program Files\MS USB Display\tool\x64\devcon.exe" update "C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\indirectdisplaydriver2.inf" MS\IddBus2 MD5: 8C7D36AD908F5F1A5E39F95AC92581F5)
        • conhost.exe (PID: 2364 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • devcon.exe (PID: 6596 cmdline: "C:\Program Files\MS USB Display\tool\x64\devcon.exe" restart =display MD5: 8C7D36AD908F5F1A5E39F95AC92581F5)
        • conhost.exe (PID: 652 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
  • svchost.exe (PID: 2508 cmdline: C:\Windows\system32\svchost.exe -k DcomLaunch -p -s DeviceInstall MD5: 9520A99E77D6196D0D09833146424113)
    • drvinst.exe (PID: 6200 cmdline: DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\MSUSBDisplay.inf" "9" "410771dbb" "00000000000001B0" "WinSta0\Default" "00000000000001B4" "208" "C:\Program Files\MS USB Display\lib_usb" MD5: 100997A8B475B1D1B173BE8941DFE1A6)
      • rundll32.exe (PID: 2476 cmdline: rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{c7e09768-3410-4444-b1d2-e0b7886720f1} Global\{f21d5126-d58b-9449-be56-9c74edde3b9c} C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.inf C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.cat MD5: F68AF942FD7CCC0E7BAB1A2335D2AD26)
    • drvinst.exe (PID: 5372 cmdline: DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{4f28a4ee-4f02-fd4b-b4ab-c641fe84e6a5}\indirectdisplaybus.inf" "9" "45a813563" "000000000000019C" "WinSta0\Default" "00000000000001AC" "208" "c:\program files\ms usb display\idd\indirectdisplaybus" MD5: 100997A8B475B1D1B173BE8941DFE1A6)
    • drvinst.exe (PID: 6656 cmdline: DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\Windows\INF\oem7.inf" "indirectdisplaybus.inf:c14ce884432a57a1:IndirectDisplayBus_Device:10.49.31.666:root\indirectdisplaybus," "45a813563" "000000000000019C" MD5: 100997A8B475B1D1B173BE8941DFE1A6)
  • IndirectDisplayBus.sys (PID: 4 cmdline: MD5: AB54EBBCB994C461CCD00DF6012C979B)
  • svchost.exe (PID: 5844 cmdline: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc MD5: 9520A99E77D6196D0D09833146424113)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpVirustotal: Detection: 7%Perma Link
Source: MSDisplay_MultiDev_v1.0.0.18.0.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\unins000.dat
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-CPSEL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-M8EPE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-K5OOJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-UFQ2L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-RDLS7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-BCJ08.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-I379N.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-HU23B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-C6QMJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-GQQN7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\arm64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\arm64\is-NFRRI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x64\is-SNENH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x64\is-23N2J.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x86\is-I7QM3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x86\is-72M4S.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\is-ETMH0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\is-HMJOS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x64\is-3VMOJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x64\is-2C1GB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x86\is-I5A5F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x86\is-DJS68.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\is-7CVUF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\is-SOASQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x64\is-V32EN.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x64\is-VL4BF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x64\is-E8IBG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x86\is-AVMSV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x86\is-0QEAF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\is-81ET8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\is-T2J7E.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\amd64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\amd64\is-CINNI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\amd64\is-PT0QG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\x86\is-4AJ4C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\x86\is-JKEU0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\is-KK37C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\is-6AV4H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x64\is-7F2TI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x86\is-BBMUU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\is-VF8R4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\is-U4EIA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x64\is-KHGPI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x86\is-2TVU1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\is-AS7LJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\is-3S2HL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x64\is-LKLT5.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x86\is-MLVJ0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\is-E04DG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\is-IQAK7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x64\is-GCO13.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x86\is-D9APK.tmp
Source: MSDisplay_MultiDev_v1.0.0.18.0.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 52.109.8.45
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 52.109.88.191
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 52.109.88.191
Source: unknownTCP traffic detected without corresponding DNS query: 52.109.8.45
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\indirectdisplaydriver1.cat (copy)Jump to dropped file
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeFile created: C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\SETD2B.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\is-ETMH0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\is-7CVUF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\displayproxy.cat (copy)Jump to dropped file
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeFile created: C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\MSUSBDisplay.cat (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\dfmirage.cat (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\indirectdisplaybus.cat (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\indirectdisplaydriver2.cat (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\is-E04DG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\is-AS7LJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\IndirectDisplayDriver0.cat (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\is-VF8R4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\is-KK37C.tmpJump to dropped file
Source: MSDisplay_MultiDev_v1.0.0.18.0.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Windows\System32\drvinst.exeFile created: C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}
Source: C:\Windows\System32\drvinst.exeFile deleted: C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\amd64\SET1065.tmp
Source: C:\Windows\System32\drvinst.exeFile created: C:\Windows\System32\DriverStore\FileRepository\msusbdisplay.inf_amd64_de17024e2b5dcc19
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess token adjusted: Load Driver
Source: C:\Windows\System32\svchost.exeProcess token adjusted: Security
Source: unknownDriver loaded: C:\Windows\System32\drivers\IndirectDisplayBus.sys
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeFile read: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeProcess created: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp "C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp" /SL5="$40132,2556185,806912,C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe"
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeProcess created: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp "C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp" /SL5="$40132,2556185,806912,C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe"
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" dp_add "C:\Program Files\MS USB Display\lib_usb\MSUSBDisplay.inf" USB\VID_534D&PID_6021&MI_03
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\MSUSBDisplay.inf" "9" "410771dbb" "00000000000001B0" "WinSta0\Default" "00000000000001B4" "208" "C:\Program Files\MS USB Display\lib_usb"
Source: C:\Windows\System32\drvinst.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{c7e09768-3410-4444-b1d2-e0b7886720f1} Global\{f21d5126-d58b-9449-be56-9c74edde3b9c} C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.inf C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.cat
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" dp_add "C:\Program Files\MS USB Display\lib_usb\MSUSBDisplay.inf" USB\VID_534D&PID_6021&MI_03
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" install "C:\Program Files\MS USB Display\idd\indirectdisplaybus\indirectdisplaybus.inf" root\IndirectDisplayBus
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{4f28a4ee-4f02-fd4b-b4ab-c641fe84e6a5}\indirectdisplaybus.inf" "9" "45a813563" "000000000000019C" "WinSta0\Default" "00000000000001AC" "208" "c:\program files\ms usb display\idd\indirectdisplaybus"
Source: unknownProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\Windows\INF\oem7.inf" "indirectdisplaybus.inf:c14ce884432a57a1:IndirectDisplayBus_Device:10.49.31.666:root\indirectdisplaybus," "45a813563" "000000000000019C"
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" update "C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\indirectdisplaydriver0.inf" MS\IddBus
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" update "C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\indirectdisplaydriver1.inf" MS\IddBus1
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" update "C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\indirectdisplaydriver2.inf" MS\IddBus2
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" restart =display
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p
Source: unknownProcess created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k DcomLaunch -p -s DeviceInstall
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" install "C:\Program Files\MS USB Display\idd\indirectdisplaybus\indirectdisplaybus.inf" root\IndirectDisplayBus
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" update "C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\indirectdisplaydriver0.inf" MS\IddBus
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" update "C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\indirectdisplaydriver1.inf" MS\IddBus1
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" update "C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\indirectdisplaydriver2.inf" MS\IddBus2
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\MSUSBDisplay.inf" "9" "410771dbb" "00000000000001B0" "WinSta0\Default" "00000000000001B4" "208" "C:\Program Files\MS USB Display\lib_usb"
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{4f28a4ee-4f02-fd4b-b4ab-c641fe84e6a5}\indirectdisplaybus.inf" "9" "45a813563" "000000000000019C" "WinSta0\Default" "00000000000001AC" "208" "c:\program files\ms usb display\idd\indirectdisplaybus"
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\Windows\INF\oem7.inf" "indirectdisplaybus.inf:c14ce884432a57a1:IndirectDisplayBus_Device:10.49.31.666:root\indirectdisplaybus," "45a813563" "000000000000019C"
Source: C:\Windows\System32\drvinst.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{c7e09768-3410-4444-b1d2-e0b7886720f1} Global\{f21d5126-d58b-9449-be56-9c74edde3b9c} C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.inf C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.cat
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess created: C:\Program Files\MS USB Display\tool\x64\devcon.exe "C:\Program Files\MS USB Display\tool\x64\devcon.exe" restart =display
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Users\user\AppData\Local\Programs
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeFile created: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp
Source: classification engineClassification label: mal60.evad.winEXE@34/119@0/13
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile read: C:\Program Files\desktop.ini
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Windows\System32\drvinst.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{c7e09768-3410-4444-b1d2-e0b7886720f1} Global\{f21d5126-d58b-9449-be56-9c74edde3b9c} C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.inf C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.cat
Source: C:\Windows\System32\drvinst.exeMutant created: \BaseNamedObjects\DrvInst.exe_mutex_{5B10AC83-4F13-4fde-8C0B-B85681BA8D73}
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2364:120:WilError_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2364:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4700:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7164:120:WilError_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1984:120:WilError_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:652:120:WilError_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1984:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4700:120:WilError_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1288:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7164:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1288:120:WilError_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:652:304:WilStaging_02
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpWindow found: window name: TMainForm
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{509DC88F-BC75-4AED-B511-9892EAD1AE48}}_is1
Source: MSDisplay_MultiDev_v1.0.0.18.0.exeStatic file information: File size 3275933 > 1048576
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\unins000.dat
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-CPSEL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-M8EPE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-K5OOJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-UFQ2L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-RDLS7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-BCJ08.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-I379N.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-HU23B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-C6QMJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\is-GQQN7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\arm64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\arm64\is-NFRRI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x64\is-SNENH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x64\is-23N2J.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x86\is-I7QM3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\tool\x86\is-72M4S.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\is-ETMH0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\is-HMJOS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x64\is-3VMOJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x64\is-2C1GB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x86\is-I5A5F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\video_driver\x86\is-DJS68.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\is-7CVUF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\is-SOASQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x64\is-V32EN.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x64\is-VL4BF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x64\is-E8IBG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x86\is-AVMSV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\displayproxy\x86\is-0QEAF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\is-81ET8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\is-T2J7E.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\amd64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\amd64\is-CINNI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\amd64\is-PT0QG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\x86\is-4AJ4C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\lib_usb\x86\is-JKEU0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\is-KK37C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\is-6AV4H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x64\is-7F2TI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x86\is-BBMUU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\is-VF8R4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\is-U4EIA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x64\is-KHGPI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x86\is-2TVU1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\is-AS7LJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\is-3S2HL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x64\is-LKLT5.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x86\is-MLVJ0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\is-E04DG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\is-IQAK7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x64
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x64\is-GCO13.tmp
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x86
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDirectory created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x86\is-D9APK.tmp
Source: MSDisplay_MultiDev_v1.0.0.18.0.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE

Data Obfuscation

barindex
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeProcess created: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp "C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp" /SL5="$40132,2556185,806912,C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe"
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeProcess created: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp "C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp" /SL5="$40132,2556185,806912,C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe"
Source: MSDisplay_MultiDev_v1.0.0.18.0.exeStatic PE information: section name: .didata
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\x86\is-I5A5F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyKmd.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\x86\is-I7QM3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x64\is-7F2TI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\WinUsbDisplay.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x86\DisplayProxyKmd.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x86\indirectdisplaydriver0.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x64\IndirectDisplayDriver1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x86\IndirectDisplayBus.sys (copy)Jump to dropped file
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeFile created: C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\x86\libusb0_x86.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x86\IndirectDisplayDriver2.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x64\is-GCO13.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\lib_usb\x86\is-4AJ4C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x86\is-MLVJ0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\libyuv.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x86\IndirectDisplayDriver1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\x64\is-3VMOJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x64\IndirectDisplayBus.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\is-I379N.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\x64\is-SNENH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x64\is-E8IBG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\arm64\is-NFRRI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\x64\is-23N2J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\is-UFQ2L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\is-RDLS7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\unins000.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\libVMonitor.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x64\is-LKLT5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\x64\devcon.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x86\is-BBMUU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x64\indirectdisplaydriver0.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Users\user\AppData\Local\Temp\is-P1C7O.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeFile created: C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\amd64\SETCCB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\libusb0.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyUmd32.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x86\is-D9APK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\x64\dfmirage.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\x86\dfmirage.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\lib_usb\x86\libusb0.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\lib_usb\amd64\is-PT0QG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\arm64\devcon.exe (copy)Jump to dropped file
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeFile created: C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\amd64\libusb0.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\x86\dpinst.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\x86\is-DJS68.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\lib_usb\amd64\libusb0.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\x86\devcon.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\is-CPSEL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\is-M8EPE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x64\is-KHGPI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\msvcr120.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\x64\is-2C1GB.tmpJump to dropped file
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeFile created: C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\x86\SETD6B.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\is-BCJ08.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x64\is-VL4BF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x86\is-AVMSV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\x86\is-72M4S.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\x64\dfmirage.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\video_driver\x86\dfmirage.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x64\is-V32EN.tmpJump to dropped file
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeFile created: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x86\is-2TVU1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\tool\x64\dpinst.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x86\DisplayProxyUmd.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x86\is-0QEAF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyUmd.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x64\IndirectDisplayDriver2.dll (copy)Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\dfmirage\DEVICE0 Attach.ToDesktop
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MS USB Display
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MS USB Display\MS USB Display.lnk
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MS USB Display\Uninstall MS USB Display.lnk
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpRegistry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Hardware Profiles\0001\System\CurrentControlSet\SERVICES\dfmirage\DEVICE0
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Windows Usb Display
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Windows Usb Display
Source: C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\video_driver\x86\is-I5A5F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyKmd.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x64\is-7F2TI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\tool\x86\is-I7QM3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\WinUsbDisplay.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x86\DisplayProxyKmd.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x86\indirectdisplaydriver0.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x64\IndirectDisplayDriver1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x86\IndirectDisplayBus.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x86\IndirectDisplayDriver2.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x64\is-GCO13.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\lib_usb\x86\is-4AJ4C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x86\is-MLVJ0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\libyuv.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x86\IndirectDisplayDriver1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\video_driver\x64\is-3VMOJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x64\IndirectDisplayBus.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\is-I379N.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x64\is-E8IBG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\tool\arm64\is-NFRRI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\tool\x64\is-23N2J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\is-UFQ2L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\is-RDLS7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\unins000.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\libVMonitor.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x64\is-LKLT5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaybus\x86\is-BBMUU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x64\indirectdisplaydriver0.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-P1C7O.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\amd64\SETCCB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyUmd32.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x86\is-D9APK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\video_driver\x64\dfmirage.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\video_driver\x86\dfmirage.sys (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\lib_usb\amd64\is-PT0QG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\tool\arm64\devcon.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\tool\x86\dpinst.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\video_driver\x86\is-DJS68.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\tool\x86\devcon.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\is-CPSEL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\is-M8EPE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x64\is-KHGPI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\msvcr120.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\video_driver\x64\is-2C1GB.tmpJump to dropped file
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\x86\SETD6B.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\is-BCJ08.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x64\is-VL4BF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x86\is-AVMSV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\tool\x86\is-72M4S.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\video_driver\x64\dfmirage.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\video_driver\x86\dfmirage.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x64\is-V32EN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x86\is-2TVU1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\tool\x64\dpinst.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x86\DisplayProxyUmd.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x64\IndirectDisplayDriver2.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyUmd.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpDropped PE file which has not been started: C:\Program Files\MS USB Display\displayproxy\x86\is-0QEAF.tmpJump to dropped file
Source: C:\Windows\System32\svchost.exeFile opened / queried: SCSI#Disk&Ven_VMware&Prod_Virtual_disk#5&1ec51bf7&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpProcess information queried: ProcessInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\Windows\System32 FullSizeInformation
Source: C:\Windows\System32\drvinst.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe c:\windows\system32\pnpui.dll,installsecuritypromptrundllw 20 global\{c7e09768-3410-4444-b1d2-e0b7886720f1} global\{f21d5126-d58b-9449-be56-9c74edde3b9c} c:\windows\system32\driverstore\temp\{d4cea893-464e-c84d-a474-130257eafc14}\msusbdisplay.inf c:\windows\system32\driverstore\temp\{d4cea893-464e-c84d-a474-130257eafc14}\msusbdisplay.cat
Source: unknownProcess created: C:\Windows\System32\drvinst.exe drvinst.exe "4" "0" "c:\users\user\appdata\local\temp\{4f28a4ee-4f02-fd4b-b4ab-c641fe84e6a5}\indirectdisplaybus.inf" "9" "45a813563" "000000000000019c" "winsta0\default" "00000000000001ac" "208" "c:\program files\ms usb display\idd\indirectdisplaybus"
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\drvinst.exe drvinst.exe "4" "0" "c:\users\user\appdata\local\temp\{4f28a4ee-4f02-fd4b-b4ab-c641fe84e6a5}\indirectdisplaybus.inf" "9" "45a813563" "000000000000019c" "winsta0\default" "00000000000001ac" "208" "c:\program files\ms usb display\idd\indirectdisplaybus"
Source: C:\Windows\System32\drvinst.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe c:\windows\system32\pnpui.dll,installsecuritypromptrundllw 20 global\{c7e09768-3410-4444-b1d2-e0b7886720f1} global\{f21d5126-d58b-9449-be56-9c74edde3b9c} c:\windows\system32\driverstore\temp\{d4cea893-464e-c84d-a474-130257eafc14}\msusbdisplay.inf c:\windows\system32\driverstore\temp\{d4cea893-464e-c84d-a474-130257eafc14}\msusbdisplay.cat
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmpQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\drvinst.exeQueries volume information: C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.cat VolumeInformation
Source: C:\Windows\System32\drvinst.exeQueries volume information: C:\Windows\System32\DriverStore\Temp\{d4cea893-464e-c84d-a474-130257eafc14}\MSUSBDisplay.cat VolumeInformation
Source: C:\Program Files\MS USB Display\tool\x64\devcon.exeQueries volume information: C:\Program Files\MS USB Display\idd\indirectdisplaybus\indirectdisplaybus.cat VolumeInformation
Source: C:\Windows\System32\drvinst.exeQueries volume information: C:\Windows\System32\DriverStore\Temp\{89a7b30b-5d54-3847-bfe2-75606a79c7b8}\IndirectDisplayBus.cat VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Windows\System32\drvinst.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Windows\System32\svchost.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center cval
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\svchost.exeWMI Queries: AntiVirusProduct.instanceGuid="{D68DDC3A-831F-4fae-9E44-DA132C1ACF46}"
Source: C:\Windows\System32\drvinst.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD Blob
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts1
Windows Management Instrumentation
11
Windows Service
11
Windows Service
23
Masquerading
OS Credential Dumping13
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default Accounts11
Command and Scripting Interpreter
111
Registry Run Keys / Startup Folder
1
Process Injection
2
Virtualization/Sandbox Evasion
LSASS Memory2
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)2
LSASS Driver
111
Registry Run Keys / Startup Folder
11
Disable or Modify Tools
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)2
LSASS Driver
1
Process Injection
NTDS2
System Owner/User Discovery
Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
Deobfuscate/Decode Files or Information
LSA Secrets1
File and Directory Discovery
SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.common1
Rundll32
Cached Domain Credentials23
System Information Discovery
VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
External Remote ServicesScheduled TaskStartup ItemsStartup Items1
File Deletion
DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
MSDisplay_MultiDev_v1.0.0.18.0.exe2%ReversingLabs
MSDisplay_MultiDev_v1.0.0.18.0.exe4%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp7%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp7%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\is-P1C7O.tmp\_isetup\_setup64.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-P1C7O.tmp\_isetup\_setup64.tmp0%VirustotalBrowse
C:\Program Files\MS USB Display\WinUsbDisplay.exe (copy)0%ReversingLabs
C:\Program Files\MS USB Display\WinUsbDisplay.exe (copy)3%VirustotalBrowse
C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyKmd.sys (copy)0%ReversingLabs
C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyKmd.sys (copy)0%VirustotalBrowse
C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyUmd.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyUmd.dll (copy)0%VirustotalBrowse
C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyUmd32.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\displayproxy\x64\DisplayProxyUmd32.dll (copy)0%VirustotalBrowse
C:\Program Files\MS USB Display\displayproxy\x86\DisplayProxyKmd.sys (copy)0%ReversingLabs
C:\Program Files\MS USB Display\displayproxy\x86\DisplayProxyUmd.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\idd\indirectdisplaybus\x64\IndirectDisplayBus.sys (copy)0%ReversingLabs
C:\Program Files\MS USB Display\idd\indirectdisplaybus\x86\IndirectDisplayBus.sys (copy)0%ReversingLabs
C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x64\indirectdisplaydriver0.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\idd\indirectdisplaydriver0\x86\indirectdisplaydriver0.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x64\IndirectDisplayDriver1.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\idd\indirectdisplaydriver1\x86\IndirectDisplayDriver1.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x64\IndirectDisplayDriver2.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\idd\indirectdisplaydriver2\x86\IndirectDisplayDriver2.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\is-BCJ08.tmp0%ReversingLabs
C:\Program Files\MS USB Display\is-CPSEL.tmp5%ReversingLabs
C:\Program Files\MS USB Display\is-I379N.tmp2%ReversingLabs
C:\Program Files\MS USB Display\is-RDLS7.tmp0%ReversingLabs
C:\Program Files\MS USB Display\is-UFQ2L.tmp0%ReversingLabs
C:\Program Files\MS USB Display\lib_usb\amd64\is-PT0QG.tmp0%ReversingLabs
C:\Program Files\MS USB Display\lib_usb\x86\is-4AJ4C.tmp0%ReversingLabs
C:\Program Files\MS USB Display\tool\arm64\devcon.exe (copy)0%ReversingLabs
C:\Program Files\MS USB Display\tool\x64\devcon.exe (copy)0%ReversingLabs
C:\Program Files\MS USB Display\tool\x64\dpinst.exe (copy)0%ReversingLabs
C:\Program Files\MS USB Display\tool\x86\devcon.exe (copy)0%ReversingLabs
C:\Program Files\MS USB Display\tool\x86\dpinst.exe (copy)0%ReversingLabs
C:\Program Files\MS USB Display\video_driver\x64\dfmirage.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\video_driver\x64\dfmirage.sys (copy)0%ReversingLabs
C:\Program Files\MS USB Display\video_driver\x86\dfmirage.dll (copy)0%ReversingLabs
C:\Program Files\MS USB Display\video_driver\x86\dfmirage.sys (copy)0%ReversingLabs
C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\amd64\SETCCB.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\{8117b47f-4301-c348-a35a-e6484dccdb3c}\x86\SETD6B.tmp0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
52.109.8.45
unknownUnited States
8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
192.229.221.95
unknownUnited States
15133EDGECASTUSfalse
52.109.88.191
unknownUnited States
8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
Joe Sandbox Version:37.0.0 Beryl
Analysis ID:838207
Start date and time:2023-03-30 17:12:31 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
Number of analysed new started processes analysed:25
Number of new started drivers analysed:1
Number of existing processes analysed:1
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
Analysis Mode:stream
Analysis stop reason:Timeout
Sample file name:MSDisplay_MultiDev_v1.0.0.18.0.exe
Detection:MAL
Classification:mal60.evad.winEXE@34/119@0/13
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): SIHClient.exe, SgrmBroker.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 40.126.32.140, 20.190.160.14, 40.126.32.133, 20.190.160.20, 40.126.32.72, 40.126.32.68, 40.126.32.74, 20.190.160.17, 40.126.32.76, 40.126.32.138, 20.190.160.22
  • Excluded domains from analysis (whitelisted): prdv6a.aadg.msidentity.com, slscr.update.microsoft.com, login.live.com, www.tm.lg.prod.aadmsa.akadns.net, www.tm.v6.a.prd.aadg.trafficmanager.net, www.tm.v6.a.prd.aadg.akadns.net, login.msa.msidentity.com, www.tm.lg.prod.aadmsa.trafficmanager.net
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • VT rate limit hit for: C:\Program Files\MS USB Display\displayproxy\x86\DisplayProxyKmd.sys (copy)
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):298
Entropy (8bit):4.709089164337212
Encrypted:false
SSDEEP:
MD5:7F4207EA1304993E8533B7A58F3A51B0
SHA1:4BEB49C0869F6BA1E86033C5372A2F3DB3CC36C0
SHA-256:EE8078A7D68D5F9B702C1F5E322D67227A6512E75247D9E950D497E753C62565
SHA-512:63ACE6218308612522E86D4B925D51B4D3E7BD1E34D38662BD7C29F488AAF64EBE8B23D90A56235BE06FDB5E6D4151EAA86A2D617CCFCEA07414BF893AB75290
Malicious:false
Reputation:low
Preview:If there is an exception in the program, feedback the file of WinUsbDisplay.log to technical support department .....1.The default location of this file is "C:\Users\xxx\AppData\Roaming\WinUsbDisplay\WinUsbDisplay.log"....2. you can also find the file of WinUsbDisplay.log by running logpath.bat...
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):1512448
Entropy (8bit):6.386797587254736
Encrypted:false
SSDEEP:
MD5:4AAB73E5792E49227E5843C0207E7BFD
SHA1:AF013C0150D5F30687A7072491F7A5E4FCC23024
SHA-256:85AF24188A2040F61F008C50620835B9DDCEA0F4C1707447EC11002D55ED134E
SHA-512:8B65FBF8854B8030B9145FB0F6087933BF9E48AEB0CB855F8B90D120AECE3649EB5B9947F8AC6D0185F8D23A369A0C08EFD4AFE6E4A5BAC284FB33804E30F819
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 3%, Browse
Reputation:low
Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.........v.............eL.....eL.G...eL.....4.......4.......4.........c....../.....N.......#..................X...#.......#.............#.......Rich............................PE..L....".`.................R...................p....@..........................`............@.................................d...T.......0..........................P...T...............................@............p..d............................text....Q.......R.................. ..`.rdata.......p.......V..............@..@.data...0X... ...D..................@....tls.................J..............@....rsrc...0............L..............@..@.reloc..............V..............@..B................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Unicode text, UTF-8 text
Category:dropped
Size (bytes):353
Entropy (8bit):5.849396057301375
Encrypted:false
SSDEEP:
MD5:AB5BD4D46AA4F19ED52961F81635AD76
SHA1:37F3E26449DA284D16C28847413294DFBEC2A2DB
SHA-256:A1C6CEDAB9EC5850C98D5FED2CB0A2253FBBCCA7B8C5974F57F34FBDE4DC3C3F
SHA-512:C744DABDD16FD08E8AD0D625AF97CDB82F3D3E45E20FF783DCEBB448B22FBEC5AD95125CD371ABAB1BBD335173062312B244DCE97076AAE88A84A2C0CAA14A6D
Malicious:false
Reputation:low
Preview:[mem_by_pass_scale].width=400.height=200..[picture_quality].pqmode=1..[frame_swtich].; .... 0...... 1.RGB888.RGB565.....frame_switch_enable=3.; .............(frame_Enable = 2) 12.....12...565. 20.....20...888.frame_avg_fre_0=42.frame_avg_fre_1=18.frame_time=3..
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):2411
Entropy (8bit):5.559929036972021
Encrypted:false
SSDEEP:
MD5:735FDCE617E9F71AE9A798B88C232B7D
SHA1:E9A0820807161B3D8BC9C3CD29DC2580EFDD80A2
SHA-256:A9CD9D499AADCDB3F2968C1A96EAF6AE983AF38529D4303AF52E64FE81CE4268
SHA-512:1766C410BAEC5A421DF3036226FB4F249B6D307FF7E8C0071CBF3AF6467423BA2244E7ABD585E5C04C189C6FE41CF96151C18E79C9BC335EC9CF7F21037BB1B3
Malicious:false
Reputation:low
Preview:..[Version]..Signature = "$Windows NT$"..Class=System..ClassGUID={4d36e97d-e325-11ce-bfc1-08002be10318}..Provider=%MNF%..DriverVer = 09/19/2021,15.47.24.217..CatalogFile=DisplayProxy.cat..PnpLockdown=1....[DestinationDirs]..Displayproxykmd.CopyFiles = 12 ; drivers..Displayproxyumd.CopyFiles = 11 ; system32..Displayproxyumdwow.CopyFiles = 10, SysWow64 ; x64-specific....[SourceDisksFiles.x86]..DisplayProxyKmd.sys=1,x86..DisplayProxyUmd.dll=1,x86....[SourceDisksFiles.amd64]..DisplayProxyKmd.sys=1,x64..DisplayProxyUmd.dll=1,x64..DisplayProxyUmd32.dll=1,x64....[SourceDisksNames.x86]..1 = %DiskName%....[SourceDisksNames.amd64]..1 = %DiskName%......[Manufacturer]..%MNF%=MNF,NTx86,NTamd64....[MNF.NTx86]..;..;.Allow the driver to be loaded on VGA and XGA..;.."Ultrasemi Display Device" = Display_Inst, Root\UltrasemiDisplayProxy....[MNF.NTamd64]..;..;.Allow the driver to be loaded on VGA and XGA..;.."Ultrasemi Display Device" = Display_Inst, Root\Ult
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):13832
Entropy (8bit):7.413790710533066
Encrypted:false
SSDEEP:
MD5:CD3DF3274F80B319AC8C4A57F38098E9
SHA1:7CE7F6825439F147EEB0BEF7BB7298F389F9CBDD
SHA-256:072248ABB8D759370C07F3BAF2C69CF8EE3C48C19657D8D0D89587A6FE0963A9
SHA-512:79D00C04140FE777926C5A1D393118B275A065872E73C42AAABF6814A2993B5DCCE821DD15B964A98B7B0E60485F82C9A27EF6164364385D8DEAB538B13B8730
Malicious:false
Reputation:low
Preview:0.6...*.H........5.0.5....1.0...`.H.e......0..!..+.....7......0...0...+.....7......vw..0tM..V0z.....211124112001Z0...+.....7.....0..80......U..!.........R.21..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0N..+.....7...1@0>...F.i.l.e.......,d.i.s.p.l.a.y.p.r.o.x.y.u.m.d.3.2...d.l.l...0....+49...P.........iy.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0J..+.....7...1<0:...F.i.l.e.......(d.i.s.p.l.a.y.p.r.o.x.y.k.m.d...s.y.s...0.... N...=1.|..j..Z.........'.[...L.C1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0N..+.....7...1@0>...F.i.l.e.......,d.i.s.p.l.a.y.p.r.o.x.y.u.m.d.3.2...d.l.l...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... N...=1.|..j..Z.........'.[...L.C0......Y..v./.7....4..j1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0N..+.....7...1@0>...F.i.l.e.......,d.i.s.p.l.a.y.p.r.o.x.y.u.m.d.3.2...d.l.l...0.... ..I..........:.).0:..d...Bh1..0.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):13832
Entropy (8bit):7.413790710533066
Encrypted:false
SSDEEP:
MD5:CD3DF3274F80B319AC8C4A57F38098E9
SHA1:7CE7F6825439F147EEB0BEF7BB7298F389F9CBDD
SHA-256:072248ABB8D759370C07F3BAF2C69CF8EE3C48C19657D8D0D89587A6FE0963A9
SHA-512:79D00C04140FE777926C5A1D393118B275A065872E73C42AAABF6814A2993B5DCCE821DD15B964A98B7B0E60485F82C9A27EF6164364385D8DEAB538B13B8730
Malicious:false
Reputation:low
Preview:0.6...*.H........5.0.5....1.0...`.H.e......0..!..+.....7......0...0...+.....7......vw..0tM..V0z.....211124112001Z0...+.....7.....0..80......U..!.........R.21..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0N..+.....7...1@0>...F.i.l.e.......,d.i.s.p.l.a.y.p.r.o.x.y.u.m.d.3.2...d.l.l...0....+49...P.........iy.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0J..+.....7...1<0:...F.i.l.e.......(d.i.s.p.l.a.y.p.r.o.x.y.k.m.d...s.y.s...0.... N...=1.|..j..Z.........'.[...L.C1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0N..+.....7...1@0>...F.i.l.e.......,d.i.s.p.l.a.y.p.r.o.x.y.u.m.d.3.2...d.l.l...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... N...=1.|..j..Z.........'.[...L.C0......Y..v./.7....4..j1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0N..+.....7...1@0>...F.i.l.e.......,d.i.s.p.l.a.y.p.r.o.x.y.u.m.d.3.2...d.l.l...0.... ..I..........:.).0:..d...Bh1..0.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):2411
Entropy (8bit):5.559929036972021
Encrypted:false
SSDEEP:
MD5:735FDCE617E9F71AE9A798B88C232B7D
SHA1:E9A0820807161B3D8BC9C3CD29DC2580EFDD80A2
SHA-256:A9CD9D499AADCDB3F2968C1A96EAF6AE983AF38529D4303AF52E64FE81CE4268
SHA-512:1766C410BAEC5A421DF3036226FB4F249B6D307FF7E8C0071CBF3AF6467423BA2244E7ABD585E5C04C189C6FE41CF96151C18E79C9BC335EC9CF7F21037BB1B3
Malicious:false
Reputation:low
Preview:..[Version]..Signature = "$Windows NT$"..Class=System..ClassGUID={4d36e97d-e325-11ce-bfc1-08002be10318}..Provider=%MNF%..DriverVer = 09/19/2021,15.47.24.217..CatalogFile=DisplayProxy.cat..PnpLockdown=1....[DestinationDirs]..Displayproxykmd.CopyFiles = 12 ; drivers..Displayproxyumd.CopyFiles = 11 ; system32..Displayproxyumdwow.CopyFiles = 10, SysWow64 ; x64-specific....[SourceDisksFiles.x86]..DisplayProxyKmd.sys=1,x86..DisplayProxyUmd.dll=1,x86....[SourceDisksFiles.amd64]..DisplayProxyKmd.sys=1,x64..DisplayProxyUmd.dll=1,x64..DisplayProxyUmd32.dll=1,x64....[SourceDisksNames.x86]..1 = %DiskName%....[SourceDisksNames.amd64]..1 = %DiskName%......[Manufacturer]..%MNF%=MNF,NTx86,NTamd64....[MNF.NTx86]..;..;.Allow the driver to be loaded on VGA and XGA..;.."Ultrasemi Display Device" = Display_Inst, Root\UltrasemiDisplayProxy....[MNF.NTamd64]..;..;.Allow the driver to be loaded on VGA and XGA..;.."Ultrasemi Display Device" = Display_Inst, Root\Ult
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):89576
Entropy (8bit):6.653478980768659
Encrypted:false
SSDEEP:
MD5:74EB1436CFD88C6B5667CE61C74EBCE9
SHA1:8CF5FE5A5184892AC78C117B41561E8F73F53805
SHA-256:9C878E6686F2FA993E27189F2F26BB5A5E179284148DFA8FDE76DC96EF95ECAA
SHA-512:A404980C25D04F9CD47419ED66281E47519882B89E8DC77C4599A13C97F05F6E1BD3FC89A8485F5E1B767D7D1D782CA681B5A8DE0CE51A575E3240ECCD5B64E7
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........x...+...+...+..*...+...+..+..*...+..*...+..*...+..*...+Rich...+........PE..d.....Fa.........."..........&.......0.........@.............................P............`A.................................................0..(............ ..$........M...@..H.......8...............................................0............................text...4........................... ..h.rdata..4...........................@..H.data...H...........................@....pdata..$.... ......................@..HINIT.........0...................... ..b.reloc..H....@......................@..B................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):175648
Entropy (8bit):6.480611220155743
Encrypted:false
SSDEEP:
MD5:6B05847B8A40B5C50ECFC094C57D0435
SHA1:6910A0D8283D359F482A9AB5C98BFF33F7BB75DF
SHA-256:FDFF39037CE9780B25738300597F878964FB90BFF4CB456B3A60396945AF682C
SHA-512:7CA7413482F0F12D13B5AF15E646183BD8A004225F3793A1250378E71FAFC7AD63BA58C4EC109EB75A867D533D845D9B2837A198DD6728AFF9DD9D4D02746C05
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........wb....S...S...S*d.R...S*d.Ri..S*d.R...S*d.R...S...S...S.c.R...S.c.R...S.c.R...S.c.R...S.c.R...S.c.R...SRich...S................PE..d...wG+a.........." .................b..............................................V.....`A........................................`B.......B..<............p..p....`.. N..........('..T............................'..8............................................text............................... ..`.rdata..............................@..@.data........P.......4..............@....pdata..p....p.......@..............@..@_RDATA...............V..............@..@.reloc...............X..............@..B................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):147536
Entropy (8bit):6.812722893465503
Encrypted:false
SSDEEP:
MD5:160036A7249B9C509CD5852A27F4DE34
SHA1:3DC281E72322FB14BF7F801E0DA8C74F42D8583E
SHA-256:D16382DD9E7334C8B518C164AB6CA7AA9F5E31D482A995F7548DDB345A0AB181
SHA-512:B68D608C913B89799C2FA32617640F7AC7BBA19074EB493B7870C5AA967DFACEB3E593AB0D58C9B77340D43BF7362AFBC97D9DC4F334B4810A77B71CAE8EA796
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..................................Y........................................................................Rich....................PE..L....G+a...........!.....^..........PU.......p............................... ............@A........................P...........<.......................PR..........\...T...............................@............p..,............................text....].......^.................. ..`.rdata...m...p...n...b..............@..@.data...H...........................@....reloc..............................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):147536
Entropy (8bit):6.812722893465503
Encrypted:false
SSDEEP:
MD5:160036A7249B9C509CD5852A27F4DE34
SHA1:3DC281E72322FB14BF7F801E0DA8C74F42D8583E
SHA-256:D16382DD9E7334C8B518C164AB6CA7AA9F5E31D482A995F7548DDB345A0AB181
SHA-512:B68D608C913B89799C2FA32617640F7AC7BBA19074EB493B7870C5AA967DFACEB3E593AB0D58C9B77340D43BF7362AFBC97D9DC4F334B4810A77B71CAE8EA796
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..................................Y........................................................................Rich....................PE..L....G+a...........!.....^..........PU.......p............................... ............@A........................P...........<.......................PR..........\...T...............................@............p..,............................text....].......^.................. ..`.rdata...m...p...n...b..............@..@.data...H...........................@....reloc..............................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):89576
Entropy (8bit):6.653478980768659
Encrypted:false
SSDEEP:
MD5:74EB1436CFD88C6B5667CE61C74EBCE9
SHA1:8CF5FE5A5184892AC78C117B41561E8F73F53805
SHA-256:9C878E6686F2FA993E27189F2F26BB5A5E179284148DFA8FDE76DC96EF95ECAA
SHA-512:A404980C25D04F9CD47419ED66281E47519882B89E8DC77C4599A13C97F05F6E1BD3FC89A8485F5E1B767D7D1D782CA681B5A8DE0CE51A575E3240ECCD5B64E7
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........x...+...+...+..*...+...+..+..*...+..*...+..*...+..*...+Rich...+........PE..d.....Fa.........."..........&.......0.........@.............................P............`A.................................................0..(............ ..$........M...@..H.......8...............................................0............................text...4........................... ..h.rdata..4...........................@..H.data...H...........................@....pdata..$.... ......................@..HINIT.........0...................... ..b.reloc..H....@......................@..B................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):175648
Entropy (8bit):6.480611220155743
Encrypted:false
SSDEEP:
MD5:6B05847B8A40B5C50ECFC094C57D0435
SHA1:6910A0D8283D359F482A9AB5C98BFF33F7BB75DF
SHA-256:FDFF39037CE9780B25738300597F878964FB90BFF4CB456B3A60396945AF682C
SHA-512:7CA7413482F0F12D13B5AF15E646183BD8A004225F3793A1250378E71FAFC7AD63BA58C4EC109EB75A867D533D845D9B2837A198DD6728AFF9DD9D4D02746C05
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........wb....S...S...S*d.R...S*d.Ri..S*d.R...S*d.R...S...S...S.c.R...S.c.R...S.c.R...S.c.R...S.c.R...S.c.R...SRich...S................PE..d...wG+a.........." .................b..............................................V.....`A........................................`B.......B..<............p..p....`.. N..........('..T............................'..8............................................text............................... ..`.rdata..............................@..@.data........P.......4..............@....pdata..p....p.......@..............@..@_RDATA...............V..............@..@.reloc...............X..............@..B................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):72680
Entropy (8bit):6.978263575533531
Encrypted:false
SSDEEP:
MD5:928F770BEE13C90A3A50FE5B223DF756
SHA1:9F0A130DE14F1EB1888CD4DA2A1A9355C5A51E70
SHA-256:5129B2ABFA81C3D3F85FCD7C83E1E66C388117042B32BB7D8C940AB4F19F5A91
SHA-512:D718FCE40CB7B7FE4D946728D7F5F76B2BB21C5B46B80493DDA3B03A4193365720843A61650C392F23857DA8C50067ACFA4A8F11627C4F770D4F172EA57C7B9B
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%..1a..ba..ba..bu..cd..ba..b,..bu..cg..b9..cm..b9..c`..bRicha..b........PE..L...B.Fa..........................................@.......................................@E................................H...<........................M..........p...8...............................@...............0............................text...4........................... ..h.rdata..............................@..H.data...p...........................@...INIT................................ ..b.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):147544
Entropy (8bit):6.812775396923209
Encrypted:false
SSDEEP:
MD5:6768220C7151A3538529D3B589B51809
SHA1:BB2F1BBC08149B38E10C35CE46B53F7E97894880
SHA-256:63DAAEBE01CD4C7F80CFA82C4BD7FEE3EB86FC5F98EA1DB86B240E46DF125740
SHA-512:F6D59316C3855284EA71FD094B4F03CB2F9A4763E303B6481AEC5110473B38BCEBC020F2DD2B7F7DCF08A316702E2E0D22AF9502246D2FD2CCFCAE539ADCEE1C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..................................Y........................................................................Rich....................PE..L....G+a...........!.....^..........PU.......p............................... ......#?....@A........................P...........<.......................XR..........\...T...............................@............p..,............................text....].......^.................. ..`.rdata...m...p...n...b..............@..@.data...H...........................@....reloc..............................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):147544
Entropy (8bit):6.812775396923209
Encrypted:false
SSDEEP:
MD5:6768220C7151A3538529D3B589B51809
SHA1:BB2F1BBC08149B38E10C35CE46B53F7E97894880
SHA-256:63DAAEBE01CD4C7F80CFA82C4BD7FEE3EB86FC5F98EA1DB86B240E46DF125740
SHA-512:F6D59316C3855284EA71FD094B4F03CB2F9A4763E303B6481AEC5110473B38BCEBC020F2DD2B7F7DCF08A316702E2E0D22AF9502246D2FD2CCFCAE539ADCEE1C
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..................................Y........................................................................Rich....................PE..L....G+a...........!.....^..........PU.......p............................... ......#?....@A........................P...........<.......................XR..........\...T...............................@............p..,............................text....].......^.................. ..`.rdata...m...p...n...b..............@..@.data...H...........................@....reloc..............................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):72680
Entropy (8bit):6.978263575533531
Encrypted:false
SSDEEP:
MD5:928F770BEE13C90A3A50FE5B223DF756
SHA1:9F0A130DE14F1EB1888CD4DA2A1A9355C5A51E70
SHA-256:5129B2ABFA81C3D3F85FCD7C83E1E66C388117042B32BB7D8C940AB4F19F5A91
SHA-512:D718FCE40CB7B7FE4D946728D7F5F76B2BB21C5B46B80493DDA3B03A4193365720843A61650C392F23857DA8C50067ACFA4A8F11627C4F770D4F172EA57C7B9B
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%..1a..ba..ba..bu..cd..ba..b,..bu..cg..b9..cm..b9..c`..bRicha..b........PE..L...B.Fa..........................................@.......................................@E................................H...<........................M..........p...8...............................@...............0............................text...4........................... ..h.rdata..............................@..H.data...p...........................@...INIT................................ ..b.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):5180
Entropy (8bit):3.6771151892091862
Encrypted:false
SSDEEP:
MD5:178FA611C571BA987D07DC96A461DD26
SHA1:FD79052547A1A9CD0B957CB39D32888EB46408E1
SHA-256:1829607F235DA2D801329F56939FAD672C2F8873E3FFC90E33222DA80DA30570
SHA-512:97AF898AB0BCAE4C4F3CA5D7E8CD4175AB8253782BC3F5D94CBBB9E0E44E921820171338230DA747AA40C6A91032564E48552278F07105331EFAB471E3F13D3F
Malicious:false
Reputation:low
Preview:..;./.*.+.+.....;.....;.C.o.p.y.r.i.g.h.t. .(.c.). .1.9.9.0.-.1.9.9.9. .M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n. .A.l.l. .r.i.g.h.t.s. .R.e.s.e.r.v.e.d.....;.....;.M.o.d.u.l.e. .N.a.m.e.:.....;.....;. . . . .i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...I.N.F.....;.....;.A.b.s.t.r.a.c.t.:.....;. . . . .I.N.F. .f.i.l.e. .f.o.r. .i.n.s.t.a.l.l.i.n.g. .t.o.a.s.t.e.r. .b.u.s. .e.n.u.m.e.r.a.t.o.r. .d.r.i.v.e.r.....;.....;.I.n.s.t.a.l.l.a.t.i.o.n. .N.o.t.e.s.:.....;. . . . .U.s.i.n.g. .D.e.v.c.o.n.:. .T.y.p.e. .".d.e.v.c.o.n. .i.n.s.t.a.l.l. .i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...i.n.f. .r.o.o.t.\.i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s.". .t.o. .i.n.s.t.a.l.l.....;.....;.-.-.*./.....[.V.e.r.s.i.o.n.].....S.i.g.n.a.t.u.r.e.=.".$.W.I.N.D.O.W.S. .N.T.$.".....C.l.a.s.s.=.S.y.s.t.e.m.....C.l.a.s.s.G.u.i.d.=.{.4.D.3.6.E.9.7.D.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....P.r.o.v.i.d.e.r.=.%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.....D.r.i.v.e.r.V.e.r. .=. .0.9./.0.5./.2.0.1.9.,.1.0...4.9...3.1.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):11371
Entropy (8bit):7.165425948476642
Encrypted:false
SSDEEP:
MD5:AB04B978A378FB420900C933DDB1223C
SHA1:BBE1A47B005C19D3B231CC87ED94763A54FC6A1D
SHA-256:E50CACA48A385F73AA1D1A36905616FE2A2767EA457D793E718C7AF323AA82DA
SHA-512:3A050824CA848AA801722E00428ED0DC86D3CC5585C7A0C14BB89344BB82DB0AF71A8B4988BC8CCD6AD78CC5CB37106B69264C970E580C05805D1F92EE827AEB
Malicious:false
Reputation:low
Preview:0.,g..*.H........,X0.,T...1.0...`.H.e......0.....+.....7......0...0...+.....7........#BG.C.zK..'..190917090926Z0...+.....7.....0...0.... .)`.#]...2.V...g,/.s....3"-....p1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0P..+.....7...1B0@...F.i.l.e........i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...i.n.f...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... .)`.#]...2.V...g,/.s....3"-....p0....M%..r09.EA.q..m.Jr..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0P..+.....7...1B0@...F.i.l.e........i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...s.y.s...0.... `v.b..]}...v...........M3c.B..31..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0P..+.....7...1B0@...F.i.l.e........i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...s.y.s...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... `v.b..]}...v...........M3c.B..30.... ...|M..S.o....,...:..u.U. ..a1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):5180
Entropy (8bit):3.6771151892091862
Encrypted:false
SSDEEP:
MD5:178FA611C571BA987D07DC96A461DD26
SHA1:FD79052547A1A9CD0B957CB39D32888EB46408E1
SHA-256:1829607F235DA2D801329F56939FAD672C2F8873E3FFC90E33222DA80DA30570
SHA-512:97AF898AB0BCAE4C4F3CA5D7E8CD4175AB8253782BC3F5D94CBBB9E0E44E921820171338230DA747AA40C6A91032564E48552278F07105331EFAB471E3F13D3F
Malicious:false
Reputation:low
Preview:..;./.*.+.+.....;.....;.C.o.p.y.r.i.g.h.t. .(.c.). .1.9.9.0.-.1.9.9.9. .M.i.c.r.o.s.o.f.t. .C.o.r.p.o.r.a.t.i.o.n. .A.l.l. .r.i.g.h.t.s. .R.e.s.e.r.v.e.d.....;.....;.M.o.d.u.l.e. .N.a.m.e.:.....;.....;. . . . .i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...I.N.F.....;.....;.A.b.s.t.r.a.c.t.:.....;. . . . .I.N.F. .f.i.l.e. .f.o.r. .i.n.s.t.a.l.l.i.n.g. .t.o.a.s.t.e.r. .b.u.s. .e.n.u.m.e.r.a.t.o.r. .d.r.i.v.e.r.....;.....;.I.n.s.t.a.l.l.a.t.i.o.n. .N.o.t.e.s.:.....;. . . . .U.s.i.n.g. .D.e.v.c.o.n.:. .T.y.p.e. .".d.e.v.c.o.n. .i.n.s.t.a.l.l. .i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...i.n.f. .r.o.o.t.\.i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s.". .t.o. .i.n.s.t.a.l.l.....;.....;.-.-.*./.....[.V.e.r.s.i.o.n.].....S.i.g.n.a.t.u.r.e.=.".$.W.I.N.D.O.W.S. .N.T.$.".....C.l.a.s.s.=.S.y.s.t.e.m.....C.l.a.s.s.G.u.i.d.=.{.4.D.3.6.E.9.7.D.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....P.r.o.v.i.d.e.r.=.%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.....D.r.i.v.e.r.V.e.r. .=. .0.9./.0.5./.2.0.1.9.,.1.0...4.9...3.1.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):11371
Entropy (8bit):7.165425948476642
Encrypted:false
SSDEEP:
MD5:AB04B978A378FB420900C933DDB1223C
SHA1:BBE1A47B005C19D3B231CC87ED94763A54FC6A1D
SHA-256:E50CACA48A385F73AA1D1A36905616FE2A2767EA457D793E718C7AF323AA82DA
SHA-512:3A050824CA848AA801722E00428ED0DC86D3CC5585C7A0C14BB89344BB82DB0AF71A8B4988BC8CCD6AD78CC5CB37106B69264C970E580C05805D1F92EE827AEB
Malicious:false
Reputation:low
Preview:0.,g..*.H........,X0.,T...1.0...`.H.e......0.....+.....7......0...0...+.....7........#BG.C.zK..'..190917090926Z0...+.....7.....0...0.... .)`.#]...2.V...g,/.s....3"-....p1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0P..+.....7...1B0@...F.i.l.e........i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...i.n.f...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... .)`.#]...2.V...g,/.s....3"-....p0....M%..r09.EA.q..m.Jr..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0P..+.....7...1B0@...F.i.l.e........i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...s.y.s...0.... `v.b..]}...v...........M3c.B..31..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0P..+.....7...1B0@...F.i.l.e........i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.b.u.s...s.y.s...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... `v.b..]}...v...........M3c.B..30.... ...|M..S.o....,...:..u.U. ..a1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):25592
Entropy (8bit):6.445554864082489
Encrypted:false
SSDEEP:
MD5:AB54EBBCB994C461CCD00DF6012C979B
SHA1:6BEB75137C7D27CAAF41202467FC1036BC4D140D
SHA-256:8519B438E73E6858B4CE56815F4E287325A35BF184F180BF196501EE457D92C9
SHA-512:6E00CC524E5897040C2503EAC4112FF538F3A5EF5AA6FBEF2457A3178A84F1885478E2C0598FFFC90118D9FC6AB68FBC120B6699A407313693BD5290C70902DC
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........P..c...c...c..e...c..f...c..d...c...b...c..b...c..g...c..`...c...g...c.......c...a...c.Rich..c.........................PE..d.....].........."......$.....................@....................................[.....`A.................................................p..<............P.......@...#......,....1..8............................1...............0..H............................text...0........................... ..h.rdata.......0......................@..H.data...8....@....... ..............@....pdata.......P......."..............@..HPAGE.........`.......$.............. ..`INIT.........p.......2.............. ..b.rsrc................4..............@..B.reloc..,............>..............@..B................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):25592
Entropy (8bit):6.445554864082489
Encrypted:false
SSDEEP:
MD5:AB54EBBCB994C461CCD00DF6012C979B
SHA1:6BEB75137C7D27CAAF41202467FC1036BC4D140D
SHA-256:8519B438E73E6858B4CE56815F4E287325A35BF184F180BF196501EE457D92C9
SHA-512:6E00CC524E5897040C2503EAC4112FF538F3A5EF5AA6FBEF2457A3178A84F1885478E2C0598FFFC90118D9FC6AB68FBC120B6699A407313693BD5290C70902DC
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........P..c...c...c..e...c..f...c..d...c...b...c..b...c..g...c..`...c...g...c.......c...a...c.Rich..c.........................PE..d.....].........."......$.....................@....................................[.....`A.................................................p..<............P.......@...#......,....1..8............................1...............0..H............................text...0........................... ..h.rdata.......0......................@..H.data...8....@....... ..............@....pdata.......P......."..............@..HPAGE.........`.......$.............. ..`INIT.........p.......2.............. ..b.rsrc................4..............@..B.reloc..,............>..............@..B................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):24568
Entropy (8bit):6.4893145797760505
Encrypted:false
SSDEEP:
MD5:7E95DAB6E06427D3AC1105BF637035D3
SHA1:15FEC0EE39F04DC2CEA1125431099A782B1093A2
SHA-256:174E5860B4F62FE8BCA1FA965BD20860CEB91E3ADE7D179A7E6FC9346E5260B9
SHA-512:EF987E0260BD7A5789D6B5BBBE693C1F989335F0A7591D758E2F1925B91734561BB06A36E817416C388B29B4D7C100606A02083572F9F7D1C5A34568E634DF60
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........!8..@V..@V..@V..&P..@V..&S..@V..&U..@V..&Q..@V..@W..@V..&W..@V..&R..@V.o)R..@V.o)...@V.o)T..@V.Rich.@V.................PE..L.....]................."...................0....@.......................................@E................................l`..<....p...............<...#...... ...@1..8...........................x1...............0..$............................text............................... ..h.rdata..h....0......................@..H.data........@......................@...PAGE.........P...................... ..`INIT.........`.......,.............. ..b.rsrc........p......................@..B.reloc.. ............8..............@..B................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):24568
Entropy (8bit):6.4893145797760505
Encrypted:false
SSDEEP:
MD5:7E95DAB6E06427D3AC1105BF637035D3
SHA1:15FEC0EE39F04DC2CEA1125431099A782B1093A2
SHA-256:174E5860B4F62FE8BCA1FA965BD20860CEB91E3ADE7D179A7E6FC9346E5260B9
SHA-512:EF987E0260BD7A5789D6B5BBBE693C1F989335F0A7591D758E2F1925B91734561BB06A36E817416C388B29B4D7C100606A02083572F9F7D1C5A34568E634DF60
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........!8..@V..@V..@V..&P..@V..&S..@V..&U..@V..&Q..@V..@W..@V..&W..@V..&R..@V.o)R..@V.o)...@V.o)T..@V.Rich.@V.................PE..L.....]................."...................0....@.......................................@E................................l`..<....p...............<...#...... ...@1..8...........................x1...............0..$............................text............................... ..h.rdata..h....0......................@..H.data........@......................@...PAGE.........P...................... ..`INIT.........`.......,.............. ..b.rsrc........p......................@..B.reloc.. ............8..............@..B................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):11401
Entropy (8bit):7.158998538079764
Encrypted:false
SSDEEP:
MD5:C9E4AADDD74CBE283866ABC68E8C38E6
SHA1:EE8E8EDAEFC3C2190502F99B4AC28458520F4D27
SHA-256:A3CD2595275F0CA648F7BF12E891BAF51A639A6C05D6142DD7FF579B6A142248
SHA-512:09302DD35D8A16FE31D73D2F917CA84B8A06EDD04E2EF2C179AD02C50237CE30D4C45EAE674B91D2BAA15051091F4DCAE0F75CF573267ECDC52AEC83F826A36E
Malicious:false
Reputation:low
Preview:0.,...*.H........,v0.,r...1.0...`.H.e......0.....+.....7......0...0...+.....7..........2,M.7....'..190917090927Z0...+.....7.....0...0.... .R.. .J....ey...A1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.0...i.n.f...0..'. Q`.7s..J.(...r......)...=.[...}1...0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.0...d.l.l...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... Q`.7s..J.(...r......)...=.[...}0.........Wm..u$d.....+.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.0...d.l.l...0.... ......t.=..BZ.Mh."..3.p...9..\.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... ......t.=..BZ.Mh."..
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):4948
Entropy (8bit):3.733316347789815
Encrypted:false
SSDEEP:
MD5:F509D3DD341F960C05FE0EDF3BAFC5AE
SHA1:20EE52EDD420A14AE0ED81BABEDE6579B6E5E041
SHA-256:A7D613CB1B9C74BC3DF9E2425A9D4D681E22E3C2AF339E7093F00539C2075CEC
SHA-512:0551BD4508A0FF7A06C1037E48AB42966E70D3664B707CABE3D74F0C76311567D8AD238012FC79E8B3FDBCA78FF55847740F8B785D5C69CEBDDDB4F9D760977A
Malicious:false
Reputation:low
Preview:..;.....;. .I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.0...i.n.f.....;.........[.V.e.r.s.i.o.n.].....S.i.g.n.a.t.u.r.e.=.".$.W.i.n.d.o.w.s. .N.T.$.".....;.C.l.a.s.s. . . . . . . .=.S.y.s.t.e.m.....;.C.l.a.s.s.G.u.i.d. . . .=.{.4.D.3.6.E.9.7.D.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....C.l.a.s.s.G.U.I.D. .=. .{.4.D.3.6.E.9.6.8.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....C.l.a.s.s. .=. .D.i.s.p.l.a.y.....C.l.a.s.s.V.e.r. .=. .2...0.....P.r.o.v.i.d.e.r.=.%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.....C.a.t.a.l.o.g.F.i.l.e.=.I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.0...c.a.t.....D.r.i.v.e.r.V.e.r. .=. .0.9./.0.5./.2.0.1.9.,.1.0...5.0...4.7...8.8.9.........[.M.a.n.u.f.a.c.t.u.r.e.r.].....%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.=.S.t.a.n.d.a.r.d.,.N.T.x.8.6.,.N.T.a.m.d.6.4.........[.S.t.a.n.d.a.r.d...N.T.x.8.6.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.t.a.n.d.a.r.d...N.T.a.m.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):4948
Entropy (8bit):3.733316347789815
Encrypted:false
SSDEEP:
MD5:F509D3DD341F960C05FE0EDF3BAFC5AE
SHA1:20EE52EDD420A14AE0ED81BABEDE6579B6E5E041
SHA-256:A7D613CB1B9C74BC3DF9E2425A9D4D681E22E3C2AF339E7093F00539C2075CEC
SHA-512:0551BD4508A0FF7A06C1037E48AB42966E70D3664B707CABE3D74F0C76311567D8AD238012FC79E8B3FDBCA78FF55847740F8B785D5C69CEBDDDB4F9D760977A
Malicious:false
Reputation:low
Preview:..;.....;. .I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.0...i.n.f.....;.........[.V.e.r.s.i.o.n.].....S.i.g.n.a.t.u.r.e.=.".$.W.i.n.d.o.w.s. .N.T.$.".....;.C.l.a.s.s. . . . . . . .=.S.y.s.t.e.m.....;.C.l.a.s.s.G.u.i.d. . . .=.{.4.D.3.6.E.9.7.D.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....C.l.a.s.s.G.U.I.D. .=. .{.4.D.3.6.E.9.6.8.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....C.l.a.s.s. .=. .D.i.s.p.l.a.y.....C.l.a.s.s.V.e.r. .=. .2...0.....P.r.o.v.i.d.e.r.=.%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.....C.a.t.a.l.o.g.F.i.l.e.=.I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.0...c.a.t.....D.r.i.v.e.r.V.e.r. .=. .0.9./.0.5./.2.0.1.9.,.1.0...5.0...4.7...8.8.9.........[.M.a.n.u.f.a.c.t.u.r.e.r.].....%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.=.S.t.a.n.d.a.r.d.,.N.T.x.8.6.,.N.T.a.m.d.6.4.........[.S.t.a.n.d.a.r.d...N.T.x.8.6.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.t.a.n.d.a.r.d...N.T.a.m.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):11401
Entropy (8bit):7.158998538079764
Encrypted:false
SSDEEP:
MD5:C9E4AADDD74CBE283866ABC68E8C38E6
SHA1:EE8E8EDAEFC3C2190502F99B4AC28458520F4D27
SHA-256:A3CD2595275F0CA648F7BF12E891BAF51A639A6C05D6142DD7FF579B6A142248
SHA-512:09302DD35D8A16FE31D73D2F917CA84B8A06EDD04E2EF2C179AD02C50237CE30D4C45EAE674B91D2BAA15051091F4DCAE0F75CF573267ECDC52AEC83F826A36E
Malicious:false
Reputation:low
Preview:0.,...*.H........,v0.,r...1.0...`.H.e......0.....+.....7......0...0...+.....7..........2,M.7....'..190917090927Z0...+.....7.....0...0.... .R.. .J....ey...A1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.0...i.n.f...0..'. Q`.7s..J.(...r......)...=.[...}1...0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.0...d.l.l...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... Q`.7s..J.(...r......)...=.[...}0.........Wm..u$d.....+.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.0...d.l.l...0.... ......t.=..BZ.Mh."..3.p...9..\.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... ......t.=..BZ.Mh."..
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):85496
Entropy (8bit):5.959824332165052
Encrypted:false
SSDEEP:
MD5:9D237DFDB4D1449B4704969BA13BADD5
SHA1:43905EC237632E744DADE006EBEA87403F892799
SHA-256:6B9C1DAA21F9CC0202FC6DFEBF5CAA221EAF2BBE32F2267D9523C3EC7925617B
SHA-512:B72E1BBCEEBB129789DC9BA46CA23ADE9B777067C0513E33FD237CB2FB8AF678B9D99A5B0212533CC5CD21D684F0E3D5971AFF5E841F84BF088BEF0F3D210426
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H'.&t.&t.&t.."u.&t..%u.&t..#u.&t..!u.&t..t.&t..'u.&t.'t..&t...t.&t...t.&t...t.&t].#u.&t].&u.&t].$u.&tRich.&t........................PE..d......].........." .........t...............................................p...........`A........................................`...`....................@.......*...#...`..........8........................... ................................................text...)........................... ..`.rdata...P.......R..................@..@.data........0......................@....pdata.......@......................@..@.reloc.......`.......&..............@..B................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):85496
Entropy (8bit):5.959824332165052
Encrypted:false
SSDEEP:
MD5:9D237DFDB4D1449B4704969BA13BADD5
SHA1:43905EC237632E744DADE006EBEA87403F892799
SHA-256:6B9C1DAA21F9CC0202FC6DFEBF5CAA221EAF2BBE32F2267D9523C3EC7925617B
SHA-512:B72E1BBCEEBB129789DC9BA46CA23ADE9B777067C0513E33FD237CB2FB8AF678B9D99A5B0212533CC5CD21D684F0E3D5971AFF5E841F84BF088BEF0F3D210426
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H'.&t.&t.&t.."u.&t..%u.&t..#u.&t..!u.&t..t.&t..'u.&t.'t..&t...t.&t...t.&t...t.&t].#u.&t].&u.&t].$u.&tRich.&t........................PE..d......].........." .........t...............................................p...........`A........................................`...`....................@.......*...#...`..........8........................... ................................................text...)........................... ..`.rdata...P.......R..................@..@.data........0......................@....pdata.......@......................@..@.reloc.......`.......&..............@..B................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):67064
Entropy (8bit):6.460881273142044
Encrypted:false
SSDEEP:
MD5:B0CFA27BC81CE56D53C4166EA648B6DA
SHA1:A46A3ACD696D27291AD82D632729CC1F0F85E5A0
SHA-256:8FCB7B639145FAFB6A76D175E8FFDE05E0EC5B83936F2067DCD74BB657FB778B
SHA-512:19179F242C39F8C99D4345690061DE07E69AF1BC9D946A0929942CF88DF972DCEC27C63ADEC08CA81B28D5ED78577CFF21FC7851DEACEA5C5D1DC974E59E4834
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e.[...[...[.......W.......S.......y...>...Z...R.O...>...^...[...........Y.......Z.......X.......Z.......Z...Rich[...........PE..L......]...........!.........F.......r....................................................@A............................d...T............................#......`.......8...........................H................................................text.............................. ..`.rdata...5.......6..................@..@.data...............................@....reloc..`...........................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):67064
Entropy (8bit):6.460881273142044
Encrypted:false
SSDEEP:
MD5:B0CFA27BC81CE56D53C4166EA648B6DA
SHA1:A46A3ACD696D27291AD82D632729CC1F0F85E5A0
SHA-256:8FCB7B639145FAFB6A76D175E8FFDE05E0EC5B83936F2067DCD74BB657FB778B
SHA-512:19179F242C39F8C99D4345690061DE07E69AF1BC9D946A0929942CF88DF972DCEC27C63ADEC08CA81B28D5ED78577CFF21FC7851DEACEA5C5D1DC974E59E4834
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e.[...[...[.......W.......S.......y...>...Z...R.O...>...^...[...........Y.......Z.......X.......Z.......Z...Rich[...........PE..L......]...........!.........F.......r....................................................@A............................d...T............................#......`.......8...........................H................................................text.............................. ..`.rdata...5.......6..................@..@.data...............................@....reloc..`...........................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):4718
Entropy (8bit):3.7226462001402583
Encrypted:false
SSDEEP:
MD5:1A290DD0ED585F9EBA8B69E0DFE83A46
SHA1:6E875E206C6329BBABCF10C6F432B1FDFC27CDF1
SHA-256:670FBF9CB56901358AE42B70E3E01078814CDC088DB3E761E075D8169028D3CE
SHA-512:57B8D36B45D4738918C3B4EBB20C2CD36C3CACA0C9B3B805DC10E1F1F6E0C320AE7225F444C4FA3FCD9FE71173C18DD3A7C421745318840073AEEC4BD0B2577E
Malicious:false
Reputation:low
Preview:..;.....;. .I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.1...i.n.f.....;.........[.V.e.r.s.i.o.n.].....S.i.g.n.a.t.u.r.e.=.".$.W.i.n.d.o.w.s. .N.T.$.".....C.l.a.s.s.G.U.I.D. .=. .{.4.D.3.6.E.9.6.8.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....C.l.a.s.s. .=. .D.i.s.p.l.a.y.....C.l.a.s.s.V.e.r. .=. .2...0.....P.r.o.v.i.d.e.r.=.%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.....C.a.t.a.l.o.g.F.i.l.e.=.I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.1...c.a.t.....D.r.i.v.e.r.V.e.r. .=. .0.9./.0.5./.2.0.1.9.,.1.0...5.2...1.3...6.8.........[.M.a.n.u.f.a.c.t.u.r.e.r.].....%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.=.S.t.a.n.d.a.r.d.,.N.T.x.8.6.,.N.T.a.m.d.6.4.........[.S.t.a.n.d.a.r.d...N.T.x.8.6.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.1.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.t.a.n.d.a.r.d...N.T.a.m.d.6.4.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.1.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.o.u.r.c.e.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):11403
Entropy (8bit):7.165808540835695
Encrypted:false
SSDEEP:
MD5:DE33FADEDA395BE70345A8DD3FE66F3D
SHA1:8662C74F217EB22FA50F6C888A43AA61931DD625
SHA-256:C37DBB3A4A0589D22DE4AC734D257FF7692EB5B8B6E9DAE3014D5D42C0F78BCD
SHA-512:6EF4EEB94C8D06AEB28C57C2237FCDC3275CA13CFB8B645FCA4E553631B09B2ADC99298186A2B875DC98EE56CB36DBCA92016148C99A87DD9BB8C6A49E054913
Malicious:false
Reputation:low
Preview:0.,...*.H........,x0.,t...1.0...`.H.e......0.....+.....7......0...0...+.....7.....f......O.........190917090927Z0...+.....7.....0...0....%....jv.>..e='.0...1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.1...d.l.l...0.... g....i.5..+p...x.L.....a.u...(..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... g....i.5..+p...x.L.....a.u...(..0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.1...i.n.f...0..'. j...."_>..L..T.]x.....R.8.f..t1...0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.1...d.l.l...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... j...."_>..L..T.]x.....R.8.f..t0....n.^ lc)......2...'..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):4718
Entropy (8bit):3.7226462001402583
Encrypted:false
SSDEEP:
MD5:1A290DD0ED585F9EBA8B69E0DFE83A46
SHA1:6E875E206C6329BBABCF10C6F432B1FDFC27CDF1
SHA-256:670FBF9CB56901358AE42B70E3E01078814CDC088DB3E761E075D8169028D3CE
SHA-512:57B8D36B45D4738918C3B4EBB20C2CD36C3CACA0C9B3B805DC10E1F1F6E0C320AE7225F444C4FA3FCD9FE71173C18DD3A7C421745318840073AEEC4BD0B2577E
Malicious:false
Reputation:low
Preview:..;.....;. .I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.1...i.n.f.....;.........[.V.e.r.s.i.o.n.].....S.i.g.n.a.t.u.r.e.=.".$.W.i.n.d.o.w.s. .N.T.$.".....C.l.a.s.s.G.U.I.D. .=. .{.4.D.3.6.E.9.6.8.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....C.l.a.s.s. .=. .D.i.s.p.l.a.y.....C.l.a.s.s.V.e.r. .=. .2...0.....P.r.o.v.i.d.e.r.=.%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.....C.a.t.a.l.o.g.F.i.l.e.=.I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.1...c.a.t.....D.r.i.v.e.r.V.e.r. .=. .0.9./.0.5./.2.0.1.9.,.1.0...5.2...1.3...6.8.........[.M.a.n.u.f.a.c.t.u.r.e.r.].....%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.=.S.t.a.n.d.a.r.d.,.N.T.x.8.6.,.N.T.a.m.d.6.4.........[.S.t.a.n.d.a.r.d...N.T.x.8.6.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.1.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.t.a.n.d.a.r.d...N.T.a.m.d.6.4.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.1.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.o.u.r.c.e.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):11403
Entropy (8bit):7.165808540835695
Encrypted:false
SSDEEP:
MD5:DE33FADEDA395BE70345A8DD3FE66F3D
SHA1:8662C74F217EB22FA50F6C888A43AA61931DD625
SHA-256:C37DBB3A4A0589D22DE4AC734D257FF7692EB5B8B6E9DAE3014D5D42C0F78BCD
SHA-512:6EF4EEB94C8D06AEB28C57C2237FCDC3275CA13CFB8B645FCA4E553631B09B2ADC99298186A2B875DC98EE56CB36DBCA92016148C99A87DD9BB8C6A49E054913
Malicious:false
Reputation:low
Preview:0.,...*.H........,x0.,t...1.0...`.H.e......0.....+.....7......0...0...+.....7.....f......O.........190917090927Z0...+.....7.....0...0....%....jv.>..e='.0...1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.1...d.l.l...0.... g....i.5..+p...x.L.....a.u...(..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... g....i.5..+p...x.L.....a.u...(..0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.1...i.n.f...0..'. j...."_>..L..T.]x.....R.8.f..t1...0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.1...d.l.l...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... j...."_>..L..T.]x.....R.8.f..t0....n.^ lc)......2...'..1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):85496
Entropy (8bit):5.9600020449564175
Encrypted:false
SSDEEP:
MD5:CBBB8ACB68E87B5DE9A19DB85662C6CF
SHA1:92B573A79FCC475AB469907D5D1E84577654EA9C
SHA-256:8340F3295C287ADF4A972387198BE4B679535403D699920CCE7C6B2DB9D85ECF
SHA-512:E4B62791EF36352971E503825E5109EDCB4C7FDF1490E09CA85FEFC8DF3DFE96E0EE5A2208DA79828F36034EB1F62C076B9397C1608D55325E71E84B6714EA42
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H'.&t.&t.&t.."u.&t..%u.&t..#u.&t..!u.&t..t.&t..'u.&t.'t..&t...t.&t...t.&t...t.&t].#u.&t].&u.&t].$u.&tRich.&t........................PE..d......].........." .........t...............................................p.......6....`A........................................`...`....................@.......*...#...`..........8........................... ................................................text...)........................... ..`.rdata...P.......R..................@..@.data........0......................@....pdata.......@......................@..@.reloc.......`.......&..............@..B................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):85496
Entropy (8bit):5.9600020449564175
Encrypted:false
SSDEEP:
MD5:CBBB8ACB68E87B5DE9A19DB85662C6CF
SHA1:92B573A79FCC475AB469907D5D1E84577654EA9C
SHA-256:8340F3295C287ADF4A972387198BE4B679535403D699920CCE7C6B2DB9D85ECF
SHA-512:E4B62791EF36352971E503825E5109EDCB4C7FDF1490E09CA85FEFC8DF3DFE96E0EE5A2208DA79828F36034EB1F62C076B9397C1608D55325E71E84B6714EA42
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H'.&t.&t.&t.."u.&t..%u.&t..#u.&t..!u.&t..t.&t..'u.&t.'t..&t...t.&t...t.&t...t.&t].#u.&t].&u.&t].$u.&tRich.&t........................PE..d......].........." .........t...............................................p.......6....`A........................................`...`....................@.......*...#...`..........8........................... ................................................text...)........................... ..`.rdata...P.......R..................@..@.data........0......................@....pdata.......@......................@..@.reloc.......`.......&..............@..B................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):67064
Entropy (8bit):6.461606527414898
Encrypted:false
SSDEEP:
MD5:A3464A7B31EE6DDBD6B243226E10B9C3
SHA1:9E3E523C2220510B346E6107F59E63CB8B4B9AF4
SHA-256:47A10E729356565E3E7176B99659F5A9E8036F860C29FF79780F055F14172D7D
SHA-512:98741533F1C49B6AB9EB40A5F1D119E506952EC009717C67AA2286BCE9A80D7D5BEE73E01DDDA1BEE3E0C9377F4894A85F54A9B721518CD1D9F8815E03B8041D
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e.[...[...[.......W.......S.......y...>...Z...R.O...>...^...[...........Y.......Z.......X.......Z.......Z...Rich[...........PE..L......]...........!.........F.......r..............................................%.....@A............................d...d............................#......d... ...8...........................X................................................text.............................. ..`.rdata...5.......6..................@..@.data...............................@....reloc..d...........................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):67064
Entropy (8bit):6.461606527414898
Encrypted:false
SSDEEP:
MD5:A3464A7B31EE6DDBD6B243226E10B9C3
SHA1:9E3E523C2220510B346E6107F59E63CB8B4B9AF4
SHA-256:47A10E729356565E3E7176B99659F5A9E8036F860C29FF79780F055F14172D7D
SHA-512:98741533F1C49B6AB9EB40A5F1D119E506952EC009717C67AA2286BCE9A80D7D5BEE73E01DDDA1BEE3E0C9377F4894A85F54A9B721518CD1D9F8815E03B8041D
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e.[...[...[.......W.......S.......y...>...Z...R.O...>...^...[...........Y.......Z.......X.......Z.......Z...Rich[...........PE..L......]...........!.........F.......r..............................................%.....@A............................d...d............................#......d... ...8...........................X................................................text.............................. ..`.rdata...5.......6..................@..@.data...............................@....reloc..d...........................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):4720
Entropy (8bit):3.7246366000888695
Encrypted:false
SSDEEP:
MD5:FF38793324E4AF343573524225F2A4A3
SHA1:E48CDE0AD711982C6611D39FA0A969C23A8E84C4
SHA-256:25C7A126C122AD18FE4EC50BFCFB911DDB95FFBE80719FD5BECD5BBA8852C759
SHA-512:2AF0D13A9D5A3812B8D17F24F61479FB22A420F47BBFF5F8CC299AF964CB8FA55D1966C1C742AABFA5E476F2027FAB74C5B898E9E3AC78DAB75A411422C77987
Malicious:false
Reputation:low
Preview:..;.....;. .I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.2...i.n.f.....;.........[.V.e.r.s.i.o.n.].....S.i.g.n.a.t.u.r.e.=.".$.W.i.n.d.o.w.s. .N.T.$.".....C.l.a.s.s.G.U.I.D. .=. .{.4.D.3.6.E.9.6.8.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....C.l.a.s.s. .=. .D.i.s.p.l.a.y.....C.l.a.s.s.V.e.r. .=. .2...0.....P.r.o.v.i.d.e.r.=.%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.....C.a.t.a.l.o.g.F.i.l.e.=.I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.2...c.a.t.....D.r.i.v.e.r.V.e.r. .=. .0.9./.0.5./.2.0.1.9.,.1.0...5.2...3.9...1.0.0.........[.M.a.n.u.f.a.c.t.u.r.e.r.].....%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.=.S.t.a.n.d.a.r.d.,.N.T.x.8.6.,.N.T.a.m.d.6.4.........[.S.t.a.n.d.a.r.d...N.T.x.8.6.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.2.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.t.a.n.d.a.r.d...N.T.a.m.d.6.4.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.2.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.o.u.r.c.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):11402
Entropy (8bit):7.1683328662372725
Encrypted:false
SSDEEP:
MD5:64447CBD6BDF03BF174273E82BD0C852
SHA1:848F25616C3ED5C32CD9A6039193DD60C446A2D0
SHA-256:D4411EDD20575BB8151AAA8D4894FB0D249D623D8BE76735A168F6A8C4E9E6F1
SHA-512:7C3D198FF1B679491090E5A1A8F6A4EF1EFD3CCE90E35B6F4210B058702911EB22366450609BB57C83E1683686321F403E337CB25FE5F6A639BF68D3E5EAD266
Malicious:false
Reputation:low
Preview:0.,...*.H........,w0.,s...1.0...`.H.e......0.....+.....7......0...0...+.....7............@..K....Q..190917090927Z0...+.....7.....0...0..'. ..c..P..Sy/)..V.sG....\..Eo..B.1...0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.2...d.l.l...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... ..c..P..Sy/)..V.sG....\..Eo..B.0.... %.&."...N..........q...[..R.Y1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... %.&."...N..........q...[..R.Y0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.2...i.n.f...0......\..;s..7.)..Q....1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.2...d.l.l...0..........,f....i.:...1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):11402
Entropy (8bit):7.1683328662372725
Encrypted:false
SSDEEP:
MD5:64447CBD6BDF03BF174273E82BD0C852
SHA1:848F25616C3ED5C32CD9A6039193DD60C446A2D0
SHA-256:D4411EDD20575BB8151AAA8D4894FB0D249D623D8BE76735A168F6A8C4E9E6F1
SHA-512:7C3D198FF1B679491090E5A1A8F6A4EF1EFD3CCE90E35B6F4210B058702911EB22366450609BB57C83E1683686321F403E337CB25FE5F6A639BF68D3E5EAD266
Malicious:false
Reputation:low
Preview:0.,...*.H........,w0.,s...1.0...`.H.e......0.....+.....7......0...0...+.....7............@..K....Q..190917090927Z0...+.....7.....0...0..'. ..c..P..Sy/)..V.sG....\..Eo..B.1...0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.2...d.l.l...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... ..c..P..Sy/)..V.sG....\..Eo..B.0.... %.&."...N..........q...[..R.Y1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0U..+.....7...1G0E0...+.....7.......010...`.H.e....... %.&."...N..........q...[..R.Y0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.2...i.n.f...0......\..;s..7.)..Q....1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0X..+.....7...1J0H...F.i.l.e.......6i.n.d.i.r.e.c.t.d.i.s.p.l.a.y.d.r.i.v.e.r.2...d.l.l...0..........,f....i.:...1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):4720
Entropy (8bit):3.7246366000888695
Encrypted:false
SSDEEP:
MD5:FF38793324E4AF343573524225F2A4A3
SHA1:E48CDE0AD711982C6611D39FA0A969C23A8E84C4
SHA-256:25C7A126C122AD18FE4EC50BFCFB911DDB95FFBE80719FD5BECD5BBA8852C759
SHA-512:2AF0D13A9D5A3812B8D17F24F61479FB22A420F47BBFF5F8CC299AF964CB8FA55D1966C1C742AABFA5E476F2027FAB74C5B898E9E3AC78DAB75A411422C77987
Malicious:false
Reputation:low
Preview:..;.....;. .I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.2...i.n.f.....;.........[.V.e.r.s.i.o.n.].....S.i.g.n.a.t.u.r.e.=.".$.W.i.n.d.o.w.s. .N.T.$.".....C.l.a.s.s.G.U.I.D. .=. .{.4.D.3.6.E.9.6.8.-.E.3.2.5.-.1.1.C.E.-.B.F.C.1.-.0.8.0.0.2.B.E.1.0.3.1.8.}.....C.l.a.s.s. .=. .D.i.s.p.l.a.y.....C.l.a.s.s.V.e.r. .=. .2...0.....P.r.o.v.i.d.e.r.=.%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.....C.a.t.a.l.o.g.F.i.l.e.=.I.n.d.i.r.e.c.t.D.i.s.p.l.a.y.D.r.i.v.e.r.2...c.a.t.....D.r.i.v.e.r.V.e.r. .=. .0.9./.0.5./.2.0.1.9.,.1.0...5.2...3.9...1.0.0.........[.M.a.n.u.f.a.c.t.u.r.e.r.].....%.M.a.n.u.f.a.c.t.u.r.e.r.N.a.m.e.%.=.S.t.a.n.d.a.r.d.,.N.T.x.8.6.,.N.T.a.m.d.6.4.........[.S.t.a.n.d.a.r.d...N.T.x.8.6.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.2.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.t.a.n.d.a.r.d...N.T.a.m.d.6.4.].....%.D.e.v.i.c.e.N.a.m.e.%.=.M.y.D.e.v.i.c.e._.I.n.s.t.a.l.l.,. .M.S.\.I.d.d.B.u.s.2.;. .T.O.D.O.:. .e.d.i.t. .h.w.-.i.d.........[.S.o.u.r.c.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):85496
Entropy (8bit):5.95834138790578
Encrypted:false
SSDEEP:
MD5:2E3C6F7E0EFC3A6E4B01AC7D276148A5
SHA1:C45CB4E05E36085A4EC142B820D599E6E25F721B
SHA-256:63085EA17E1B8B10DF669CAA2A7C5ACE0BCB57406A87784CB0D84E6200548106
SHA-512:E7CB9FC89C5458CDDA41C2E5B7AB1E38515A94ECE5DF0F104B0682A405084D446F7946F0458B714043DD1CA0ABE231DBE9A85A5D4088A66E66F2289C58C985C8
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H'.&t.&t.&t.."u.&t..%u.&t..#u.&t..!u.&t..t.&t..'u.&t.'t..&t...t.&t...t.&t...t.&t].#u.&t].&u.&t].$u.&tRich.&t........................PE..d...\..].........." .........t...............................................p............`A........................................`...`....................@.......*...#...`..........8........................... ................................................text...)........................... ..`.rdata...P.......R..................@..@.data........0......................@....pdata.......@......................@..@.reloc.......`.......&..............@..B................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):85496
Entropy (8bit):5.95834138790578
Encrypted:false
SSDEEP:
MD5:2E3C6F7E0EFC3A6E4B01AC7D276148A5
SHA1:C45CB4E05E36085A4EC142B820D599E6E25F721B
SHA-256:63085EA17E1B8B10DF669CAA2A7C5ACE0BCB57406A87784CB0D84E6200548106
SHA-512:E7CB9FC89C5458CDDA41C2E5B7AB1E38515A94ECE5DF0F104B0682A405084D446F7946F0458B714043DD1CA0ABE231DBE9A85A5D4088A66E66F2289C58C985C8
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H'.&t.&t.&t.."u.&t..%u.&t..#u.&t..!u.&t..t.&t..'u.&t.'t..&t...t.&t...t.&t...t.&t].#u.&t].&u.&t].$u.&tRich.&t........................PE..d...\..].........." .........t...............................................p............`A........................................`...`....................@.......*...#...`..........8........................... ................................................text...)........................... ..`.rdata...P.......R..................@..@.data........0......................@....pdata.......@......................@..@.reloc.......`.......&..............@..B................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):67064
Entropy (8bit):6.461970078611847
Encrypted:false
SSDEEP:
MD5:EC2BA26EAE286D411FBE7F795E27F03B
SHA1:D884B95D8EA31CB46978BAA3696E05FB5C0B4C03
SHA-256:CC334161C8213FE9AB3853BC7F18F9938BA08B5A89984843E214322DAC05C376
SHA-512:E957B3419624734321AD4623337CFF325CFB51A8E08C7F8AECF220632EAE3ED149CEE13AEB39697BE46F84ADA12D81F3B0A366EB399C00CEB7ABC89E5358816D
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e.[...[...[.......W.......S.......y...>...Z...R.O...>...^...[...........Y.......Z.......X.......Z.......Z...Rich[...........PE..L...e..]...........!.........F.......r..............................................DQ....@A............................d...d............................#......d... ...8...........................X................................................text.............................. ..`.rdata...5.......6..................@..@.data...............................@....reloc..d...........................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):67064
Entropy (8bit):6.461970078611847
Encrypted:false
SSDEEP:
MD5:EC2BA26EAE286D411FBE7F795E27F03B
SHA1:D884B95D8EA31CB46978BAA3696E05FB5C0B4C03
SHA-256:CC334161C8213FE9AB3853BC7F18F9938BA08B5A89984843E214322DAC05C376
SHA-512:E957B3419624734321AD4623337CFF325CFB51A8E08C7F8AECF220632EAE3ED149CEE13AEB39697BE46F84ADA12D81F3B0A366EB399C00CEB7ABC89E5358816D
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e.[...[...[.......W.......S.......y...>...Z...R.O...>...^...[...........Y.......Z.......X.......Z.......Z...Rich[...........PE..L...e..]...........!.........F.......r..............................................DQ....@A............................d...d............................#......d... ...8...........................X................................................text.............................. ..`.rdata...5.......6..................@..@.data...............................@....reloc..d...........................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):234400
Entropy (8bit):6.643119711667771
Encrypted:false
SSDEEP:
MD5:1954CD248E65C7C5C2D3D93DD7F91604
SHA1:FE781C2AE615AC242AAF61A2CEF46E43DCCE2058
SHA-256:761EC2283460F3E641F9C815A015698B3EB77090808768A4BF3C17439CCD0018
SHA-512:BE8D518448EA9A317067FE92EBCB71E35AD311CE9EE26E86D80CAD1C9F6392280299379E9BADFC08F31F37878C2F576DD168F6D54F19989B461642AE12792113
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........h].`;].`;].`;P..;^.`;P..;U.`;P..;Q.`;P..;_.`;...;_.`;].a;{.`;x..;r.`;x..;\.`;P..;\.`;x..;\.`;Rich].`;........PE..L....Y.Z...........!.........>......=........ ............................................@.........................01......<B..<....`...............B...Q...p..D...................................`0..@............ ...............................text............................... ..`.rdata...%... ...&..................@..@.data...p....P.......,..............@....rsrc........`.......0..............@..@.reloc..D....p.......2..............@..B........................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):298
Entropy (8bit):4.709089164337212
Encrypted:false
SSDEEP:
MD5:7F4207EA1304993E8533B7A58F3A51B0
SHA1:4BEB49C0869F6BA1E86033C5372A2F3DB3CC36C0
SHA-256:EE8078A7D68D5F9B702C1F5E322D67227A6512E75247D9E950D497E753C62565
SHA-512:63ACE6218308612522E86D4B925D51B4D3E7BD1E34D38662BD7C29F488AAF64EBE8B23D90A56235BE06FDB5E6D4151EAA86A2D617CCFCEA07414BF893AB75290
Malicious:false
Reputation:low
Preview:If there is an exception in the program, feedback the file of WinUsbDisplay.log to technical support department .....1.The default location of this file is "C:\Users\xxx\AppData\Roaming\WinUsbDisplay\WinUsbDisplay.log"....2. you can also find the file of WinUsbDisplay.log by running logpath.bat...
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):2656593
Entropy (8bit):6.395936719567122
Encrypted:false
SSDEEP:
MD5:DEF2E0EFA04057381F04119980D6D4E4
SHA1:82028B0176FC2BCFDF3C4DB0628E5298681001D5
SHA-256:3E9EE9509BB992CFE08EF8605B2F10F0B633D8B26BF6D2DCC2C5D2C94F37A3D4
SHA-512:527B20B653DFA14B7D37471666F1A37F14CFE31B476E2A7D91704188ABFEC2C4FD2AC405C661DB367E3489ECA762DADBA694E897CA4DC1F9F299C23844873E60
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 5%
Reputation:low
Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...L..\..................$..@........%.......%...@...........................)...........@......@...................@&.......%."6...p&.8....................................................`&.....................X.%.T....0&......................text.....$.......$................. ..`.itext...'....$..(....$............. ..`.data...T[....%..\....$.............@....bss.....u...p%..........................idata.."6....%..8...L%.............@....didata......0&.......%.............@....edata.......@&.......%.............@..@.tls....D....P&..........................rdata..]....`&.......%.............@..@.rsrc...8....p&.......%.............@..@..............'.......&.............@..@........................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):125
Entropy (8bit):4.908131862349433
Encrypted:false
SSDEEP:
MD5:F9E5204741AC0FFEC1662139FD77C62F
SHA1:94B9D591160D1DA261A1185625A9B3BFA607F05D
SHA-256:33A17C00E1AD43CA60D0146F3ED783108D64FCA426CD3F97D97A60FB2B1E57DF
SHA-512:E1C5B4662673AFA0095FB5880B874EB217BCC0CCFE936E8115B4E36EB27A55EF02CCF87C392B85C0DFE287076D1CFD9770A403D041AE7BB0215EB5FC7B29DAD0
Malicious:false
Reputation:low
Preview:@echo The file of WinUsbDisplay.log in your computer is: %USERPROFILE%\AppData\Roaming\WinUsbDisplay\WinUsbDisplay.log..pause
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:MS Windows icon resource - 10 icons, 48x48, 16 colors, 4 bits/pixel, 32x32, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):92854
Entropy (8bit):5.453773902492667
Encrypted:false
SSDEEP:
MD5:2098EF97358FBBDFAE0206BBCB4E2234
SHA1:3C0AC8BA58B2CE26CD50CD6990A7A8E093C16BD6
SHA-256:DE96747834EF6ED07618AA7EB89F643444F3BA01140EED263468C08A0B7BF8FE
SHA-512:FEBFBCDC6351630076973670AD29F94A6D15149C8840492FE974D6E967E82AB5D733155518F5F43127B147E89814619250D342BAB55BE09C7A5C40452E95C9A9
Malicious:false
Reputation:low
Preview:......00......h....... ......................(.......00.............. ......................h...n"........ .(....'..00.... ..%.../.. .... ......U........ .h...Nf..(...0...`...................................................................................................................................................................................................wpppwwwwwwww..pwp........xww.wwwwwwpwww.............wpwwpwwp.......................w............wpppx.......pppwp...........w.wwwwpw..................p.wp.....................www.....................wwp............w.w.xw.wwwww.w.w.xw.x................................................p.......................p.......................p...edfFGdgdfVdgFeftfGh.p...ggwwvx|.xhxv.vw.wgO.p...|v.g...~w...~|.vg.o.p...vw...~x.~x.......v.p...||w.v.w........go.p...v.|v.x.|.........|x.p...|~w..g.~wx.......go.p...wg.w~xh..........|h.p...~wv~x.....o......go.p...|w.|.............gO.p...xh.xo...........G..p...|.w..............go.p......wx..
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):975776
Entropy (8bit):6.973946282494984
Encrypted:false
SSDEEP:
MD5:7FC50D24FBF0186FF7C1734511C640C1
SHA1:70939CEE5156B97E993CAB90A70B9FEE871EE336
SHA-256:F5B3848E09E3C9AF9E764FCA6AB61E22D374707A964739373FE9692B58E9A1B4
SHA-512:765DEB4AC696794221485CB01A861CBE86F73E0EFAD2242797F35C262BE7CF5F5B2378AE29B7160A987C9177F3E71DFCBCB21A764CD6BDE6AF3D2178C8AA6328
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 2%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......S9...XlA.XlA.XlA..A.XlA.XmA.XlAQ..A.ZlAQ..AvXlAQ..A!XlAQ..A.XlAQ..A.XlAQ..A.XlAQ..A.XlARich.XlA........PE..L....|OR.........."!................D.....................................................@.........................`........R..(....p...................Q......d]..@...8...........................H...@............P...............................text............................... ..`.data...4e.......V..................@....idata.......P......................@....rsrc........p.......0..............@..@.reloc..d].......^...4..............@..B................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Unicode text, UTF-8 text
Category:dropped
Size (bytes):353
Entropy (8bit):5.849396057301375
Encrypted:false
SSDEEP:
MD5:AB5BD4D46AA4F19ED52961F81635AD76
SHA1:37F3E26449DA284D16C28847413294DFBEC2A2DB
SHA-256:A1C6CEDAB9EC5850C98D5FED2CB0A2253FBBCCA7B8C5974F57F34FBDE4DC3C3F
SHA-512:C744DABDD16FD08E8AD0D625AF97CDB82F3D3E45E20FF783DCEBB448B22FBEC5AD95125CD371ABAB1BBD335173062312B244DCE97076AAE88A84A2C0CAA14A6D
Malicious:false
Reputation:low
Preview:[mem_by_pass_scale].width=400.height=200..[picture_quality].pqmode=1..[frame_swtich].; .... 0...... 1.RGB888.RGB565.....frame_switch_enable=3.; .............(frame_Enable = 2) 12.....12...565. 20.....20...888.frame_avg_fre_0=42.frame_avg_fre_1=18.frame_time=3..
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):1512448
Entropy (8bit):6.386797587254736
Encrypted:false
SSDEEP:
MD5:4AAB73E5792E49227E5843C0207E7BFD
SHA1:AF013C0150D5F30687A7072491F7A5E4FCC23024
SHA-256:85AF24188A2040F61F008C50620835B9DDCEA0F4C1707447EC11002D55ED134E
SHA-512:8B65FBF8854B8030B9145FB0F6087933BF9E48AEB0CB855F8B90D120AECE3649EB5B9947F8AC6D0185F8D23A369A0C08EFD4AFE6E4A5BAC284FB33804E30F819
Malicious:false
Reputation:low
Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.........v.............eL.....eL.G...eL.....4.......4.......4.........c....../.....N.......#..................X...#.......#.............#.......Rich............................PE..L....".`.................R...................p....@..........................`............@.................................d...T.......0..........................P...T...............................@............p..d............................text....Q.......R.................. ..`.rdata.......p.......V..............@..@.data...0X... ...D..................@....tls.................J..............@....rsrc...0............L..............@..@.reloc..............V..............@..B................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):157696
Entropy (8bit):6.530410261503524
Encrypted:false
SSDEEP:
MD5:10BB929E9FD8B028738B46F4D3EA741E
SHA1:4C9FA3B9D175DF3652DA2DDAA0C1228E40FF8E32
SHA-256:8817EAF691058E091E3A240547B74C3E396DAFF1312F66971274C1D30C55BDE1
SHA-512:762E4166DC8364A1938CBF2A3FB299186218626699CF51EFCA851FEF15EFEF83F4C93A81454977575CBECAAB2B64DE927B0FFA1036DEB2FD044461230741AE2C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1S..P=..P=..P=..">..P=.."8.QP=.."9..P=.%9..P=.%>..P=.%8..P=.."<..P=..P<.P=.%4..P=.%=..P=.%...P=..P...P=.%?..P=.Rich.P=.........PE..L....j.a...........!................m=....................................................@.........................`C......dD..d....p..............................t2..p............................2..@............................................text...x........................... ..`.rdata...~..........................@..@.data........P.......@..............@....rsrc........p.......L..............@..@.reloc...............R..............@..B................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):79776
Entropy (8bit):6.944446560111018
Encrypted:false
SSDEEP:
MD5:A969E398CC9319DD9BD9EEDCAE288DA7
SHA1:09B68BB4CB13B472D65E8279CAFC5FB0E736D650
SHA-256:3165D5E9212E9C4F009A594F67BD9E6D899B026CE1E3B0D6EBB994F423D6B1D1
SHA-512:99E870CCE3A8EF9DCCEE675294334C5C85794EDC5618E7C6CCC5CEE17E2A0F19D015994917BEB74F17A3814FE8914836F97067BE110E002A4A76C2CC0F7B5F65
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......l2&.(SH.(SH.(SH.qp[."SH...5./SH.(SI..SH...3.+SH...&.'SH...2.)SH...%.mSH...6.)SH...4.)SH...0.)SH.Rich(SH.................PE..L....X.L...........!........."....................@..................................Y....@.........................`...q...L............................Q...........................................6..@...............l............................text............................... ..`.data...$...........................@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):157696
Entropy (8bit):6.530410261503524
Encrypted:false
SSDEEP:
MD5:10BB929E9FD8B028738B46F4D3EA741E
SHA1:4C9FA3B9D175DF3652DA2DDAA0C1228E40FF8E32
SHA-256:8817EAF691058E091E3A240547B74C3E396DAFF1312F66971274C1D30C55BDE1
SHA-512:762E4166DC8364A1938CBF2A3FB299186218626699CF51EFCA851FEF15EFEF83F4C93A81454977575CBECAAB2B64DE927B0FFA1036DEB2FD044461230741AE2C
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1S..P=..P=..P=..">..P=.."8.QP=.."9..P=.%9..P=.%>..P=.%8..P=.."<..P=..P<.P=.%4..P=.%=..P=.%...P=..P...P=.%?..P=.Rich.P=.........PE..L....j.a...........!................m=....................................................@.........................`C......dD..d....p..............................t2..p............................2..@............................................text...x........................... ..`.rdata...~..........................@..@.data........P.......@..............@....rsrc........p.......L..............@..@.reloc...............R..............@..B................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):43456
Entropy (8bit):6.484497241431343
Encrypted:false
SSDEEP:
MD5:285954C6C6EF43B78AB84034750FAC6A
SHA1:E1F94320EAFA98D472004BC58184D70A81D96DA6
SHA-256:1ED9090015B2A896EF44C072E9662DCF78F044FF05A6B0174F2933AF11B252D1
SHA-512:6CB8ECE91B88F542108E8C743293DD8CCFF5B703279E4947ABE2866726804DEFA028E2B2E9F5907BEB553CE25BB64EBB1657BF75A45DF834ABEADA410C9428BB
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............i..i..i..h..i..?...i..?...i.d...i.d...i..?...i.d...i.d...i.d...i.Rich..i.................PE..d....Y.L.........."......t...........................................................D......................................................d...<...............|...............4...p...................................................p............................text....m.......n.................. ..h.rdata...............r..............@..H.data................x..............@....pdata..|............z..............@..HINIT.................~.............. ....rsrc...............................@..B.reloc..............................@..B........................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):43456
Entropy (8bit):6.484497241431343
Encrypted:false
SSDEEP:
MD5:285954C6C6EF43B78AB84034750FAC6A
SHA1:E1F94320EAFA98D472004BC58184D70A81D96DA6
SHA-256:1ED9090015B2A896EF44C072E9662DCF78F044FF05A6B0174F2933AF11B252D1
SHA-512:6CB8ECE91B88F542108E8C743293DD8CCFF5B703279E4947ABE2866726804DEFA028E2B2E9F5907BEB553CE25BB64EBB1657BF75A45DF834ABEADA410C9428BB
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............i..i..i..h..i..?...i..?...i.d...i.d...i..?...i.d...i.d...i.d...i.Rich..i.................PE..d....Y.L.........."......t...........................................................D......................................................d...<...............|...............4...p...................................................p............................text....m.......n.................. ..h.rdata...............r..............@..H.data................x..............@....pdata..|............z..............@..HINIT.................~.............. ....rsrc...............................@..B.reloc..............................@..B........................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):35392
Entropy (8bit):6.8172528896797715
Encrypted:false
SSDEEP:
MD5:05C10E70B437841F31E1BFA8812895BA
SHA1:C6D88AEFC87A79B067EAE889B916032FCED4C84F
SHA-256:BDBB4E35231954B342D8BC95F36633BEA3C95663B0247CFE848920587DDA5786
SHA-512:F2ACF28F058E5D6E3EC2B94B081C1884D0FD6F8F65E7B84580EE104C180833EA499B114099D43AB7B2CAB49C70158B074EA7CC1AF69638A0264308FADB6940F5
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...................................H...........!..L.!This program cannot be run in DOS mode....$.......................................................................................................................................................................................................................................................................................................................................................................................................9..{}p.(}p.(}p.(}p.(Np.($S.(xp.(Z..(gp.(Z..(|p.(Z..(|p.(Rich}p.(........PE..L....X.L.................Z...........\.......Y...............................j..............................................D\..<....a...............j.......e.......Y...............................................Y...............................text....T.......T.................. ..h.rdata..(....Y.......Y..............@..H.data...|....[.......[..............@...INIT....L....\.......\.............. ....rsrc...
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):35392
Entropy (8bit):6.8172528896797715
Encrypted:false
SSDEEP:
MD5:05C10E70B437841F31E1BFA8812895BA
SHA1:C6D88AEFC87A79B067EAE889B916032FCED4C84F
SHA-256:BDBB4E35231954B342D8BC95F36633BEA3C95663B0247CFE848920587DDA5786
SHA-512:F2ACF28F058E5D6E3EC2B94B081C1884D0FD6F8F65E7B84580EE104C180833EA499B114099D43AB7B2CAB49C70158B074EA7CC1AF69638A0264308FADB6940F5
Malicious:false
Reputation:low
Preview:MZ......................@...................................H...........!..L.!This program cannot be run in DOS mode....$.......................................................................................................................................................................................................................................................................................................................................................................................................9..{}p.(}p.(}p.(}p.(Np.($S.(xp.(Z..(gp.(Z..(|p.(Z..(|p.(Rich}p.(........PE..L....X.L.................Z...........\.......Y...............................j..............................................D\..<....a...............j.......e.......Y...............................................Y...............................text....T.......T.................. ..h.rdata..(....Y.......Y..............@..H.data...|....[.......[..............@...INIT....L....\.......\.............. ....rsrc...
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):79776
Entropy (8bit):6.944446560111018
Encrypted:false
SSDEEP:
MD5:A969E398CC9319DD9BD9EEDCAE288DA7
SHA1:09B68BB4CB13B472D65E8279CAFC5FB0E736D650
SHA-256:3165D5E9212E9C4F009A594F67BD9E6D899B026CE1E3B0D6EBB994F423D6B1D1
SHA-512:99E870CCE3A8EF9DCCEE675294334C5C85794EDC5618E7C6CCC5CEE17E2A0F19D015994917BEB74F17A3814FE8914836F97067BE110E002A4A76C2CC0F7B5F65
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......l2&.(SH.(SH.(SH.qp[."SH...5./SH.(SI..SH...3.+SH...&.'SH...2.)SH...%.mSH...6.)SH...4.)SH...0.)SH.Rich(SH.................PE..L....X.L...........!........."....................@..................................Y....@.........................`...q...L............................Q...........................................6..@...............l............................text............................... ..`.data...$...........................@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):234400
Entropy (8bit):6.643119711667771
Encrypted:false
SSDEEP:
MD5:1954CD248E65C7C5C2D3D93DD7F91604
SHA1:FE781C2AE615AC242AAF61A2CEF46E43DCCE2058
SHA-256:761EC2283460F3E641F9C815A015698B3EB77090808768A4BF3C17439CCD0018
SHA-512:BE8D518448EA9A317067FE92EBCB71E35AD311CE9EE26E86D80CAD1C9F6392280299379E9BADFC08F31F37878C2F576DD168F6D54F19989B461642AE12792113
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........h].`;].`;].`;P..;^.`;P..;U.`;P..;Q.`;P..;_.`;...;_.`;].a;{.`;x..;r.`;x..;\.`;P..;\.`;x..;\.`;Rich].`;........PE..L....Y.Z...........!.........>......=........ ............................................@.........................01......<B..<....`...............B...Q...p..D...................................`0..@............ ...............................text............................... ..`.rdata...%... ...&..................@..@.data...p....P.......,..............@....rsrc........`.......0..............@..@.reloc..D....p.......2..............@..B........................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:MS Windows icon resource - 10 icons, 48x48, 16 colors, 4 bits/pixel, 32x32, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):92854
Entropy (8bit):5.453773902492667
Encrypted:false
SSDEEP:
MD5:2098EF97358FBBDFAE0206BBCB4E2234
SHA1:3C0AC8BA58B2CE26CD50CD6990A7A8E093C16BD6
SHA-256:DE96747834EF6ED07618AA7EB89F643444F3BA01140EED263468C08A0B7BF8FE
SHA-512:FEBFBCDC6351630076973670AD29F94A6D15149C8840492FE974D6E967E82AB5D733155518F5F43127B147E89814619250D342BAB55BE09C7A5C40452E95C9A9
Malicious:false
Reputation:low
Preview:......00......h....... ......................(.......00.............. ......................h...n"........ .(....'..00.... ..%.../.. .... ......U........ .h...Nf..(...0...`...................................................................................................................................................................................................wpppwwwwwwww..pwp........xww.wwwwwwpwww.............wpwwpwwp.......................w............wpppx.......pppwp...........w.wwwwpw..................p.wp.....................www.....................wwp............w.w.xw.wwwww.w.w.xw.x................................................p.......................p.......................p...edfFGdgdfVdgFeftfGh.p...ggwwvx|.xhxv.vw.wgO.p...|v.g...~w...~|.vg.o.p...vw...~x.~x.......v.p...||w.v.w........go.p...v.|v.x.|.........|x.p...|~w..g.~wx.......go.p...wg.w~xh..........|h.p...~wv~x.....o......go.p...|w.|.............gO.p...xh.xo...........G..p...|.w..............go.p......wx..
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):125
Entropy (8bit):4.908131862349433
Encrypted:false
SSDEEP:
MD5:F9E5204741AC0FFEC1662139FD77C62F
SHA1:94B9D591160D1DA261A1185625A9B3BFA607F05D
SHA-256:33A17C00E1AD43CA60D0146F3ED783108D64FCA426CD3F97D97A60FB2B1E57DF
SHA-512:E1C5B4662673AFA0095FB5880B874EB217BCC0CCFE936E8115B4E36EB27A55EF02CCF87C392B85C0DFE287076D1CFD9770A403D041AE7BB0215EB5FC7B29DAD0
Malicious:false
Reputation:low
Preview:@echo The file of WinUsbDisplay.log in your computer is: %USERPROFILE%\AppData\Roaming\WinUsbDisplay\WinUsbDisplay.log..pause
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):975776
Entropy (8bit):6.973946282494984
Encrypted:false
SSDEEP:
MD5:7FC50D24FBF0186FF7C1734511C640C1
SHA1:70939CEE5156B97E993CAB90A70B9FEE871EE336
SHA-256:F5B3848E09E3C9AF9E764FCA6AB61E22D374707A964739373FE9692B58E9A1B4
SHA-512:765DEB4AC696794221485CB01A861CBE86F73E0EFAD2242797F35C262BE7CF5F5B2378AE29B7160A987C9177F3E71DFCBCB21A764CD6BDE6AF3D2178C8AA6328
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......S9...XlA.XlA.XlA..A.XlA.XmA.XlAQ..A.ZlAQ..AvXlAQ..A!XlAQ..A.XlAQ..A.XlAQ..A.XlAQ..A.XlARich.XlA........PE..L....|OR.........."!................D.....................................................@.........................`........R..(....p...................Q......d]..@...8...........................H...@............P...............................text............................... ..`.data...4e.......V..................@....idata.......P......................@....rsrc........p.......0..............@..@.reloc..d].......^...4..............@..B................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (console) Aarch64, for MS Windows
Category:dropped
Size (bytes):103328
Entropy (8bit):5.707075164232896
Encrypted:false
SSDEEP:
MD5:34AE27BA06A815876E4F8144DA60DD3E
SHA1:3221C3E3C620B7C179FAC1EF05BD56AFECBF7B46
SHA-256:2716D6ED1986AC28E1FE05D39D4A0C8C780B502FF87DB73EAB83460969A70BA2
SHA-512:642868FBBE1C1D289416C702228144C67DF894A9D0699E8B90BD1CFA001C03E8B9A883AF3EB8F66EDD57A1D50BCBD52E53F28ED35110A6BDCEA87BF81E39D367
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......j..(.r.{.r.{.r.{K..z<r.{K..z*r.{K..z*r.{K..z#r.{.r.{Yr.{K..z-r.{K.t{/r.{K..z/r.{Rich.r.{........PE..d.....2..........."......d..........@m.........@.....................................s....`.......... ......................................x...........x.......X....B...Q...p..........T............................................................................text....c.......d.................. ..`.rdata..r........ ...h..............@..@.data...H...........................@....pdata..X...........................@..@.rsrc...x...........................@..@.reloc.......p.......@..............@..B................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (console) Aarch64, for MS Windows
Category:dropped
Size (bytes):103328
Entropy (8bit):5.707075164232896
Encrypted:false
SSDEEP:
MD5:34AE27BA06A815876E4F8144DA60DD3E
SHA1:3221C3E3C620B7C179FAC1EF05BD56AFECBF7B46
SHA-256:2716D6ED1986AC28E1FE05D39D4A0C8C780B502FF87DB73EAB83460969A70BA2
SHA-512:642868FBBE1C1D289416C702228144C67DF894A9D0699E8B90BD1CFA001C03E8B9A883AF3EB8F66EDD57A1D50BCBD52E53F28ED35110A6BDCEA87BF81E39D367
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......j..(.r.{.r.{.r.{K..z<r.{K..z*r.{K..z*r.{K..z#r.{.r.{Yr.{K..z-r.{K.t{/r.{K..z/r.{Rich.r.{........PE..d.....2..........."......d..........@m.........@.....................................s....`.......... ......................................x...........x.......X....B...Q...p..........T............................................................................text....c.......d.................. ..`.rdata..r........ ...h..............@..@.data...H...........................@....pdata..X...........................@..@.rsrc...x...........................@..@.reloc.......p.......@..............@..B................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (console) x86-64, for MS Windows
Category:dropped
Size (bytes):103328
Entropy (8bit):5.706288910087048
Encrypted:false
SSDEEP:
MD5:8C7D36AD908F5F1A5E39F95AC92581F5
SHA1:17CC6C5E59673B8E0F37C28D012CBDBE0EB9B700
SHA-256:47B29D06A9B26E5802264CCBE1F535F63ACD3C6E6270A80E72E18219C864501B
SHA-512:A5081D6793B152F29A91456F880B21FB9E582B596BCC1CAA14DAB8565C88B153265F8EB948A685775A1E9344A9FA4F123234B5B26860531854692C6359A9C483
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........0..Q..Q..Q....H.Q....K.Q....J.Q....V.Q..Q...Q....N.Q....T.Q....I.Q..Rich.Q..........................PE..d.....2V.........."......b..........Pj.........@....................................a.....`.......... ...............................................................B...Q..............8...........................@................................................text...@a.......b.................. ..`.rdata... ......."...f..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):691616
Entropy (8bit):5.9902529204269115
Encrypted:false
SSDEEP:
MD5:3FDE18BFCF43B81A0E786FDD139636E0
SHA1:CAC3112FB0E238549DC81E56190E88DCA847CD8F
SHA-256:04373716C1A9661AD8F6713B12E9A6BA2D3112D2ECBC81EB1D40BD3ED230E268
SHA-512:F90AB2E4B5C7C4E5E1D9D13E986BB44C1EC0002E15D2DC77ACFFD9CF7D6638445D061A0AB9E03AB29A3CDE040D6CFBA57D5D34EE2520494165733DBC4C89217E
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......g9I.#X'.#X'.#X'.* ..!X'.* ..7X'.* ..<X'.#X&.Y'.* ..fX'.* ...X'...Y."X'.* .."X'.* .."X'.Rich#X'.................PE..d......J.........."..........P...............................................p......C.....@.......... ......................................H...@............0..\m...<...Q...`.......................................................................................text............................... ..`.data... ...........................@....pdata..\m...0...n..................@..@.rsrc................v..............@..@.reloc..<....`.......,..............@..B........................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (GUI) x86-64, for MS Windows
Category:dropped
Size (bytes):691616
Entropy (8bit):5.9902529204269115
Encrypted:false
SSDEEP:
MD5:3FDE18BFCF43B81A0E786FDD139636E0
SHA1:CAC3112FB0E238549DC81E56190E88DCA847CD8F
SHA-256:04373716C1A9661AD8F6713B12E9A6BA2D3112D2ECBC81EB1D40BD3ED230E268
SHA-512:F90AB2E4B5C7C4E5E1D9D13E986BB44C1EC0002E15D2DC77ACFFD9CF7D6638445D061A0AB9E03AB29A3CDE040D6CFBA57D5D34EE2520494165733DBC4C89217E
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......g9I.#X'.#X'.#X'.* ..!X'.* ..7X'.* ..<X'.#X&.Y'.* ..fX'.* ...X'...Y."X'.* .."X'.* .."X'.Rich#X'.................PE..d......J.........."..........P...............................................p......C.....@.......... ......................................H...@............0..\m...<...Q...`.......................................................................................text............................... ..`.data... ...........................@....pdata..\m...0...n..................@..@.rsrc................v..............@..@.reloc..<....`.......,..............@..B........................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (console) x86-64, for MS Windows
Category:dropped
Size (bytes):103328
Entropy (8bit):5.706288910087048
Encrypted:false
SSDEEP:
MD5:8C7D36AD908F5F1A5E39F95AC92581F5
SHA1:17CC6C5E59673B8E0F37C28D012CBDBE0EB9B700
SHA-256:47B29D06A9B26E5802264CCBE1F535F63ACD3C6E6270A80E72E18219C864501B
SHA-512:A5081D6793B152F29A91456F880B21FB9E582B596BCC1CAA14DAB8565C88B153265F8EB948A685775A1E9344A9FA4F123234B5B26860531854692C6359A9C483
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........0..Q..Q..Q....H.Q....K.Q....J.Q....V.Q..Q...Q....N.Q....T.Q....I.Q..Rich.Q..........................PE..d.....2V.........."......b..........Pj.........@....................................a.....`.......... ...............................................................B...Q..............8...........................@................................................text...@a.......b.................. ..`.rdata... ......."...f..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):97184
Entropy (8bit):5.816041772996807
Encrypted:false
SSDEEP:
MD5:D6B17CDD4CC04750A1072DB648BBF1DA
SHA1:1CB6A4B4D94475ADF77EF7134EF435896184C189
SHA-256:0E0DB9E42D04F54D9787FC26BA3CB3775D5C31B294215670B7400BC23A71BD4F
SHA-512:791C29E79128D96586ECDC10FE69B40FF6D450EE25F7A38FD25322AC1E0AE2D024335D5BF484FE8AB704AD5792801C5C5EB70E73A7181EC9E96BF08BEA32A0C2
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........:..ei..ei..ei.L.i..ei.L.i..ei.L.i..ei.L.i..ei..di..ei.L.i..ei.L.i..ei.L.i..eiRich..ei........................PE..L.....2V.................^..........0f.......p....@..........................P............@...... ..................................................*...Q...@......`...8...............................@............................................text....\.......^.................. ..`.data... ....p.......b..............@....idata..Z............d..............@..@.rsrc................t..............@..@.reloc.......@.......$..............@..B........................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):566176
Entropy (8bit):6.230921459360904
Encrypted:false
SSDEEP:
MD5:3BA6A12C0D0DBE0FFFF548D890439B8C
SHA1:8261E2331774D14951B11505BDEB0C8AAC0CC6A5
SHA-256:3BBBE096B208ED9733DC71F30060301A952BD758AA3DA34CE5B3600B1F67F0D0
SHA-512:1A099734D3C71176885C4A9795E2FCF86FD5F88A58E4F89D2251C0242B443170AAD68D19FCCB2B3AA49EE2170BF43FA488BA096660A23C8A92FEDD1B09304BDC
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......p..o4..<4..<4..<=.`<"..<=.v<...<=.f<)..<4..<@..<=.q<o..<=.a<5..<=.d<5..<Rich4..<................PE..L......J................. ...V......j........0......................................*.....@...... ..............................,....p...............R...Q...0..XC...................................=..@...............L............................text............ .................. ..`.data...`>...0.......$..............@....rsrc........p.......<..............@..@.reloc..._...0...`..................@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):566176
Entropy (8bit):6.230921459360904
Encrypted:false
SSDEEP:
MD5:3BA6A12C0D0DBE0FFFF548D890439B8C
SHA1:8261E2331774D14951B11505BDEB0C8AAC0CC6A5
SHA-256:3BBBE096B208ED9733DC71F30060301A952BD758AA3DA34CE5B3600B1F67F0D0
SHA-512:1A099734D3C71176885C4A9795E2FCF86FD5F88A58E4F89D2251C0242B443170AAD68D19FCCB2B3AA49EE2170BF43FA488BA096660A23C8A92FEDD1B09304BDC
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......p..o4..<4..<4..<=.`<"..<=.v<...<=.f<)..<4..<@..<=.q<o..<=.a<5..<=.d<5..<Rich4..<................PE..L......J................. ...V......j........0......................................*.....@...... ..............................,....p...............R...Q...0..XC...................................=..@...............L............................text............ .................. ..`.data...`>...0.......$..............@....rsrc........p.......<..............@..@.reloc..._...0...`..................@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):97184
Entropy (8bit):5.816041772996807
Encrypted:false
SSDEEP:
MD5:D6B17CDD4CC04750A1072DB648BBF1DA
SHA1:1CB6A4B4D94475ADF77EF7134EF435896184C189
SHA-256:0E0DB9E42D04F54D9787FC26BA3CB3775D5C31B294215670B7400BC23A71BD4F
SHA-512:791C29E79128D96586ECDC10FE69B40FF6D450EE25F7A38FD25322AC1E0AE2D024335D5BF484FE8AB704AD5792801C5C5EB70E73A7181EC9E96BF08BEA32A0C2
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........:..ei..ei..ei.L.i..ei.L.i..ei.L.i..ei.L.i..ei..di..ei.L.i..ei.L.i..ei.L.i..eiRich..ei........................PE..L.....2V.................^..........0f.......p....@..........................P............@...... ..................................................*...Q...@......`...8...............................@............................................text....\.......^.................. ..`.data... ....p.......b..............@....idata..Z............d..............@..@.rsrc................t..............@..@.reloc.......@.......$..............@..B........................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:InnoSetup Log 64-bit MS USB Display {509DC88F-BC75-4AED-B511-9892EAD1AE48}, version 0x418, 24852 bytes, 651689\37\user\376\, C:\Program Files\MS USB Display\376\377\37
Category:dropped
Size (bytes):24852
Entropy (8bit):3.928839236095768
Encrypted:false
SSDEEP:
MD5:337624F10E63E88E9E8BD03BA84BBCF9
SHA1:81C9A83A571485EF511A0E48892DD50635AE27FD
SHA-256:02638F0C8FF6B9C100DD9CBECD3B11D09B441A406527792E56F43759C48618BB
SHA-512:E8B028777649E8881961F3FEC57556896BBDC2D5C4B1DF0DB3B619E3383B7BC02EF588A77221337722506E9BFCFAF735DEC50CB8352E14B8553CDA44D6714364
Malicious:false
Reputation:low
Preview:Inno Setup Uninstall Log (b) 64-bit.............................{509DC88F-BC75-4AED-B511-9892EAD1AE48}}.........................................................................................MS USB Display......................................................................................................................d....a................................................................................................................................T......w........6.5.1.6.8.9......e.y.u.p......C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.M.S. .U.S.B. .D.i.s.p.l.a.y..................(.... ...... .......IFPS....&........................................................................................................ANYMETHOD.....................................................................BOOLEAN..............TWIZARDFORM....TWIZARDFORM.........TMAINFORM....TMAINFORM.........TUNINSTALLPROGRESSFORM....TUNINSTALLPROGRESSFORM.........TSETUPSTEP.........TEXECWAIT.........TMSGBOXTYPE.........TNEW
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):2656593
Entropy (8bit):6.395936719567122
Encrypted:false
SSDEEP:
MD5:DEF2E0EFA04057381F04119980D6D4E4
SHA1:82028B0176FC2BCFDF3C4DB0628E5298681001D5
SHA-256:3E9EE9509BB992CFE08EF8605B2F10F0B633D8B26BF6D2DCC2C5D2C94F37A3D4
SHA-512:527B20B653DFA14B7D37471666F1A37F14CFE31B476E2A7D91704188ABFEC2C4FD2AC405C661DB367E3489ECA762DADBA694E897CA4DC1F9F299C23844873E60
Malicious:false
Reputation:low
Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...L..\..................$..@........%.......%...@...........................)...........@......@...................@&.......%."6...p&.8....................................................`&.....................X.%.T....0&......................text.....$.......$................. ..`.itext...'....$..(....$............. ..`.data...T[....%..\....$.............@....bss.....u...p%..........................idata.."6....%..8...L%.............@....didata......0&.......%.............@....edata.......@&.......%.............@..@.tls....D....P&..........................rdata..]....`&.......%.............@..@.rsrc...8....p&.......%.............@..@..............'.......&.............@..@........................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):37087
Entropy (8bit):7.517526997242037
Encrypted:false
SSDEEP:
MD5:4725651911AD221A0CDEFF797E2C6F47
SHA1:16439B9AF9FCC660F69AA8DB8207B2C1CA597971
SHA-256:1CA7B07078B8A6DB120E162BA7C840BE0B00AB00A48E125BA6C439B601A4CB03
SHA-512:00C743871C74012F70E2CDDFC8E392EEEA81F5F99423A3A6AA4527518C5ABC18D50CE2AA1F3BA951BEE13D29D121A8D5A4F9E75E02D13D770C9591A444DB7B89
Malicious:false
Reputation:low
Preview:0.....*.H..........0......1.0...+......0.....+.....7......0...0...+.....7......oo..p$I.z.,X+/...080304162004Z0...+.....7.....0...0....R0.7.9.8.8.B.4.1.9.4.9.4.7.9.1.7.4.B.D.2.F.B.5.1.A.E.4.1.F.C.4.2.4.1.1.4.4.1.E.4...1..A02..+.....7...1$0"...O.S.A.t.t.r........2.:.5...2...0<..+.....7...1.0,...F.i.l.e........d.f.m.i.r.a.g.e...d.l.l...0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0i..+.....7...1[0Y04..+.....7...0&..... .....<.<.<.O.b.s.o.l.e.t.e.>.>.>0!0...+...........A..y.K..Q.A.BA.A.0....R6.6.3.5.A.E.F.3.1.9.0.F.B.B.C.3.9.E.1.A.1.A.D.0.D.5.F.E.5.9.5.C.6.F.A.B.7.F.E.B...1..A02..+.....7...1$0"...O.S.A.t.t.r........2.:.5...2...0<..+.....7...1.0,...F.i.l.e........d.f.m.i.r.a.g.e...s.y.s...0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0i..+.....7...1[0Y04..+.....7...0&..... .....<.<.<.O.b.s.o.l.e.t.e.>.>.>0!0...+........f5...........Y\o...0....R6.9.3.F.6.3.4.E.B.4.A.C.0.B.E.E.2.8.D.4
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):2357
Entropy (8bit):5.398666934306814
Encrypted:false
SSDEEP:
MD5:FCA869ED2E4441A235EE85EF3C35E92F
SHA1:F8710A2BFC7091B909EF990F18E70630B3DDEA84
SHA-256:71AA40B8A284EA119DA69DFCC2E1BF79EDA0A1696C09934C93EA2109CA806C4F
SHA-512:8DF3820FA92DD7ACB70D2ECB09A38FC262AD6ACAE97A4DD7FB1594FB02AA0EA9E175C373AA536DC5E063CF4E9B6F82E4C107A1551781FE03571C259579094601
Malicious:false
Reputation:low
Preview:; dfmirage.inf..;..; Installation inf for the Mirage Driver...; Copyright (c) 2002-2008 DemoForge, LLC. All rights reserved...;....[Version]..Signature="$Windows NT$"..ClassGUID={4D36E968-E325-11CE-BFC1-08002BE10318}..Class=Display..Provider=DemoForge, LLC..DriverVer=01/11/2008,2.0.105.0..CatalogFile=dfmirage.cat....[DestinationDirs]..DF.DstDir.Miniport = 12 ; \system32\drivers..DF.DstDir.Display = 11 ; \system32....;..; Driver information..;....[Manufacturer]..%DF% = DFMirage.Mfg, NTx86, NTamd64....[DFMirage.Mfg.NTx86]..%Mirage% = DFMirage, dfmirage....[DFMirage.Mfg.NTamd64]..%Mirage% = DFMirage, dfmirage....[DFMirage.Mfg]....; Models..[DFMirage]..CopyFiles= DF.DstDir.Miniport, DF.DstDir.Display....; Files..[DF.DstDir.Miniport]..dfmirage.sys....[DF.DstDir.Display]..dfmirage.dll....[DFMirage.Services]..AddService = dfmirage, 0x00000002, dfmirage_Service_Inst, dfmirage_EventLog_Inst....; Installing service..[dfmirage_Service_Inst]..ServiceType = 1 ; SERVICE_KERNEL_DRIVER.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:data
Category:dropped
Size (bytes):37087
Entropy (8bit):7.517526997242037
Encrypted:false
SSDEEP:
MD5:4725651911AD221A0CDEFF797E2C6F47
SHA1:16439B9AF9FCC660F69AA8DB8207B2C1CA597971
SHA-256:1CA7B07078B8A6DB120E162BA7C840BE0B00AB00A48E125BA6C439B601A4CB03
SHA-512:00C743871C74012F70E2CDDFC8E392EEEA81F5F99423A3A6AA4527518C5ABC18D50CE2AA1F3BA951BEE13D29D121A8D5A4F9E75E02D13D770C9591A444DB7B89
Malicious:false
Reputation:low
Preview:0.....*.H..........0......1.0...+......0.....+.....7......0...0...+.....7......oo..p$I.z.,X+/...080304162004Z0...+.....7.....0...0....R0.7.9.8.8.B.4.1.9.4.9.4.7.9.1.7.4.B.D.2.F.B.5.1.A.E.4.1.F.C.4.2.4.1.1.4.4.1.E.4...1..A02..+.....7...1$0"...O.S.A.t.t.r........2.:.5...2...0<..+.....7...1.0,...F.i.l.e........d.f.m.i.r.a.g.e...d.l.l...0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0i..+.....7...1[0Y04..+.....7...0&..... .....<.<.<.O.b.s.o.l.e.t.e.>.>.>0!0...+...........A..y.K..Q.A.BA.A.0....R6.6.3.5.A.E.F.3.1.9.0.F.B.B.C.3.9.E.1.A.1.A.D.0.D.5.F.E.5.9.5.C.6.F.A.B.7.F.E.B...1..A02..+.....7...1$0"...O.S.A.t.t.r........2.:.5...2...0<..+.....7...1.0,...F.i.l.e........d.f.m.i.r.a.g.e...s.y.s...0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0i..+.....7...1[0Y04..+.....7...0&..... .....<.<.<.O.b.s.o.l.e.t.e.>.>.>0!0...+........f5...........Y\o...0....R6.9.3.F.6.3.4.E.B.4.A.C.0.B.E.E.2.8.D.4
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:Windows setup INFormation
Category:dropped
Size (bytes):2357
Entropy (8bit):5.398666934306814
Encrypted:false
SSDEEP:
MD5:FCA869ED2E4441A235EE85EF3C35E92F
SHA1:F8710A2BFC7091B909EF990F18E70630B3DDEA84
SHA-256:71AA40B8A284EA119DA69DFCC2E1BF79EDA0A1696C09934C93EA2109CA806C4F
SHA-512:8DF3820FA92DD7ACB70D2ECB09A38FC262AD6ACAE97A4DD7FB1594FB02AA0EA9E175C373AA536DC5E063CF4E9B6F82E4C107A1551781FE03571C259579094601
Malicious:false
Reputation:low
Preview:; dfmirage.inf..;..; Installation inf for the Mirage Driver...; Copyright (c) 2002-2008 DemoForge, LLC. All rights reserved...;....[Version]..Signature="$Windows NT$"..ClassGUID={4D36E968-E325-11CE-BFC1-08002BE10318}..Class=Display..Provider=DemoForge, LLC..DriverVer=01/11/2008,2.0.105.0..CatalogFile=dfmirage.cat....[DestinationDirs]..DF.DstDir.Miniport = 12 ; \system32\drivers..DF.DstDir.Display = 11 ; \system32....;..; Driver information..;....[Manufacturer]..%DF% = DFMirage.Mfg, NTx86, NTamd64....[DFMirage.Mfg.NTx86]..%Mirage% = DFMirage, dfmirage....[DFMirage.Mfg.NTamd64]..%Mirage% = DFMirage, dfmirage....[DFMirage.Mfg]....; Models..[DFMirage]..CopyFiles= DF.DstDir.Miniport, DF.DstDir.Display....; Files..[DF.DstDir.Miniport]..dfmirage.sys....[DF.DstDir.Display]..dfmirage.dll....[DFMirage.Services]..AddService = dfmirage, 0x00000002, dfmirage_Service_Inst, dfmirage_EventLog_Inst....; Installing service..[dfmirage_Service_Inst]..ServiceType = 1 ; SERVICE_KERNEL_DRIVER.
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (native) x86-64, for MS Windows
Category:dropped
Size (bytes):65520
Entropy (8bit):6.707645180597379
Encrypted:false
SSDEEP:
MD5:398931E2E5D0500F211648A67468AEA5
SHA1:EF5310DAF008705FAA3A10A7424C6BED0B13EE0D
SHA-256:8239B9C6B9E2FDD395D488B3E5AA0FF96A8E9B3F94F644FCF7051A47F2D72130
SHA-512:B2D1312735722E236AABB0BFD3007C2D0661DE11D2130674F313A4B0F9946B48D10F0E7DEFD8208EBC7EC20AC4A5BB97C5535DC99B1BF0C9B6794B3BBDA18F7A
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\.....s...s...s...r.:.s.n,....s.?w....s.?w....s.n,....s.?w....s.?w....s.?w....s.Rich..s.........................PE..d.....G.........." .....f...........o..........................................................................................................(........................}......,....................................................................................text....a.......b.................. ..h.rdata...............f..............@..H.data................n..............@....pdata...............r..............@..HINIT.................x.............. ....rsrc................|..............@..B.reloc..............................@..B........................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):64584
Entropy (8bit):6.217578252848295
Encrypted:false
SSDEEP:
MD5:62A9F1A11D646A04527E02C5A23F5DF4
SHA1:91FD156321742014C103B13196819DDB8E119CA9
SHA-256:6062739682C36A04785FA20D234C9903F82C7CD3EEE3508E9B047156FAF3F3CA
SHA-512:CA9A0FB916AB93C47B7CD52C398F6EA77B872FA5EC666941088A1590499AE554FA299B61B83439DCFFEBF56E89A8D7C03C417090F052515CE97C6BA94932511A
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........yt......................a.......w.......g......w.......h.......f.......b.....Rich....................PE..d.....G.........."......"...N......................................................=A......................................................d...P...............,....t..H............1...............................................0...............................text............................... ..h.rdata.......0....... ..............@..H.data...\C...@...D...$..............@....pdata..,............h..............@..HINIT....`............j.............. ....rsrc................p..............@..B........................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):64584
Entropy (8bit):6.217578252848295
Encrypted:false
SSDEEP:
MD5:62A9F1A11D646A04527E02C5A23F5DF4
SHA1:91FD156321742014C103B13196819DDB8E119CA9
SHA-256:6062739682C36A04785FA20D234C9903F82C7CD3EEE3508E9B047156FAF3F3CA
SHA-512:CA9A0FB916AB93C47B7CD52C398F6EA77B872FA5EC666941088A1590499AE554FA299B61B83439DCFFEBF56E89A8D7C03C417090F052515CE97C6BA94932511A
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........yt......................a.......w.......g......w.......h.......f.......b.....Rich....................PE..d.....G.........."......"...N......................................................=A......................................................d...P...............,....t..H............1...............................................0...............................text............................... ..h.rdata.......0....... ..............@..H.data...\C...@...D...$..............@....pdata..,............h..............@..HINIT....`............j.............. ....rsrc................p..............@..B........................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (DLL) (native) x86-64, for MS Windows
Category:dropped
Size (bytes):65520
Entropy (8bit):6.707645180597379
Encrypted:false
SSDEEP:
MD5:398931E2E5D0500F211648A67468AEA5
SHA1:EF5310DAF008705FAA3A10A7424C6BED0B13EE0D
SHA-256:8239B9C6B9E2FDD395D488B3E5AA0FF96A8E9B3F94F644FCF7051A47F2D72130
SHA-512:B2D1312735722E236AABB0BFD3007C2D0661DE11D2130674F313A4B0F9946B48D10F0E7DEFD8208EBC7EC20AC4A5BB97C5535DC99B1BF0C9B6794B3BBDA18F7A
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\.....s...s...s...r.:.s.n,....s.?w....s.?w....s.n,....s.?w....s.?w....s.?w....s.Rich..s.........................PE..d.....G.........." .....f...........o..........................................................................................................(........................}......,....................................................................................text....a.......b.................. ..h.rdata...............f..............@..H.data................n..............@....pdata...............r..............@..HINIT.................x.............. ....rsrc................|..............@..B.reloc..............................@..B........................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):58480
Entropy (8bit):7.101832674821119
Encrypted:false
SSDEEP:
MD5:F06F9FF1CFE6EC762A956AE9523880BE
SHA1:161FB9F0E173F23B37A886A4FCBDBBC83E3926D5
SHA-256:5DEFD0DB776E6CB3EFCE0738727A2FA547C1E181D7269E0E488A937779578E5C
SHA-512:72BA5F1046C58EDCB93E6703AF182D51E1C5696CD505F3A70219E012ECEE8480F11540B0BBA990E1AA6A5867F2BAE523381361BE27FD63790819F02591E9648F
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...................................p...........!..L.!This program cannot be run in DOS mode....$..........................................................................................................................................................................................................................................................................................................................................................................................................@...@...@...L...B...gu..B...@...b.......C...gu..C...gu..O...gu..A...gu..A...Rich@...........................PE..L.....G...........!.....T...........L.......U...............................f...............................................[..(...._...............f...}...c.......U...............................................U...............................text...@P.......P.................. ..h.rdata.......U.......U..............@..H.data........Z.......Z..............@...INIT....
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):62280
Entropy (8bit):6.348799184399525
Encrypted:false
SSDEEP:
MD5:5FE3575C80ECA039888098C25B2CEA33
SHA1:A630387ED134F1BC608F3458C55AAD73A5131C7D
SHA-256:2E226C7EAA0D94D7FB99BF2FF86C0C6DD82774C0B45B66323A4EE8F9AD818343
SHA-512:119EE41FB04CD4A491FB545840614848D4BB359FF77E90F4C2FBE1959A1C15A6E7AF346686902E662F6624BAE9CB9AAF6D03818EED1CE74F16F97054AAA37407
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...................................`...........!..L.!This program cannot be run in DOS mode....$.........................................................................................................................................................................................................................................................................................................................................................................................................P...>...>...>..6C...>...?...>...-...>..6S...>..6P...>..6B...>..6F...>.Rich..>.................PE..L.....G.....................J.......a.......................................k......22......................................La..P....e...............k..H....i..(... ...............................@...@............................................text............................... ..h.rdata..............................@..H.data...\B.......B..................@...INIT.........a.......a..
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):62280
Entropy (8bit):6.348799184399525
Encrypted:false
SSDEEP:
MD5:5FE3575C80ECA039888098C25B2CEA33
SHA1:A630387ED134F1BC608F3458C55AAD73A5131C7D
SHA-256:2E226C7EAA0D94D7FB99BF2FF86C0C6DD82774C0B45B66323A4EE8F9AD818343
SHA-512:119EE41FB04CD4A491FB545840614848D4BB359FF77E90F4C2FBE1959A1C15A6E7AF346686902E662F6624BAE9CB9AAF6D03818EED1CE74F16F97054AAA37407
Malicious:false
Reputation:low
Preview:MZ......................@...................................`...........!..L.!This program cannot be run in DOS mode....$.........................................................................................................................................................................................................................................................................................................................................................................................................P...>...>...>..6C...>...?...>...-...>..6S...>..6P...>..6B...>..6F...>.Rich..>.................PE..L.....G.....................J.......a.......................................k......22......................................La..P....e...............k..H....i..(... ...............................@...@............................................text............................... ..h.rdata..............................@..H.data...\B.......B..................@...INIT.........a.......a..
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32 executable (DLL) (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):58480
Entropy (8bit):7.101832674821119
Encrypted:false
SSDEEP:
MD5:F06F9FF1CFE6EC762A956AE9523880BE
SHA1:161FB9F0E173F23B37A886A4FCBDBBC83E3926D5
SHA-256:5DEFD0DB776E6CB3EFCE0738727A2FA547C1E181D7269E0E488A937779578E5C
SHA-512:72BA5F1046C58EDCB93E6703AF182D51E1C5696CD505F3A70219E012ECEE8480F11540B0BBA990E1AA6A5867F2BAE523381361BE27FD63790819F02591E9648F
Malicious:false
Reputation:low
Preview:MZ......................@...................................p...........!..L.!This program cannot be run in DOS mode....$..........................................................................................................................................................................................................................................................................................................................................................................................................@...@...@...L...B...gu..B...@...b.......C...gu..C...gu..O...gu..A...gu..A...Rich@...........................PE..L.....G...........!.....T...........L.......U...............................f...............................................[..(...._...............f...}...c.......U...............................................U...............................text...@P.......P.................. ..h.rdata.......U.......U..............@..H.data........Z.......Z..............@...INIT....
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Mar 30 14:14:40 2023, mtime=Thu Mar 30 14:14:40 2023, atime=Fri May 21 07:59:26 2021, length=1512448, window=hide
Category:dropped
Size (bytes):938
Entropy (8bit):4.532506871051211
Encrypted:false
SSDEEP:
MD5:403707EB9E7DE48DE1B221D7BB005C37
SHA1:A3D9558C3ADF88039866F52BB092BE6C83765A31
SHA-256:D70403887F543602FC8A14D151F55E4BDE01FD0F133335CF8E0BCFF00FCA4FC0
SHA-512:DDEF513155EC56BC951D8339B50E95682593FD3DE969C18F1051D9B24305B76BAC269DF050091CD36116EF697232CC6D253E6D1E66DA73E05691D185C8D0CC56
Malicious:false
Reputation:low
Preview:L..................F.... ...e..Y.c.....Y.c...+...N...............................P.O. .:i.....+00.../C:\.....................1.....~V.y..PROGRA~1..t......sN.&~V.y....B...............J......U..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....f.1.....~V.y..MSUSBD~1..N......~V.y~V.y.....X........................M.S. .U.S.B. .D.i.s.p.l.a.y.....p.2......RmG .WINUSB~1.EXE..T......~V.y~V.y.....b........................W.i.n.U.s.b.D.i.s.p.l.a.y...e.x.e.......`...............-......._...........7.I`.....C:\Program Files\MS USB Display\WinUsbDisplay.exe..@.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.M.S. .U.S.B. .D.i.s.p.l.a.y.\.W.i.n.U.s.b.D.i.s.p.l.a.y...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.M.S. .U.S.B. .D.i.s.p.l.a.y.`.......X.......651689..........N...n..O...}R.....S.............N...n..O...}R.....S.............E.......9...1SPS..mD..pH.H@..=x.....h....H....F.5./EG.gM.U..............
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Mar 30 14:14:40 2023, mtime=Thu Mar 30 14:14:40 2023, atime=Thu Mar 30 14:14:40 2023, length=2656593, window=hide
Category:dropped
Size (bytes):913
Entropy (8bit):4.577020270259235
Encrypted:false
SSDEEP:
MD5:7CB8FF84307286BD9A34150C62AF2A07
SHA1:929C42AE35ED32E716871C0A151E12FCD2584F38
SHA-256:602C54F49F2BCA27FA31ED99BA63969779179F744231B694C95D525D9E08327F
SHA-512:02E3A570CB957B452FBF49882FB49C78C2A5AFBDA56A6675D9C11F6D12EC55F0DEC4221E2A7214BA6C26513F4B5FB2C0BF356669827A17B491CD52303778140D
Malicious:false
Reputation:low
Preview:L..................F.... ...RsYY.c..XutY.c..XutY.c..Q.(..........................P.O. .:i.....+00.../C:\.....................1.....~V.y..PROGRA~1..t......sN.&~V.y....B...............J......U..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....f.1.....~V.y..MSUSBD~1..N......~V.y~V.y.....X........................M.S. .U.S.B. .D.i.s.p.l.a.y.....f.2.Q.(.~V.y .unins000.exe..J......~V.y~V.y.....b.....................'..u.n.i.n.s.0.0.0...e.x.e.......[...............-.......Z...........7.I`.....C:\Program Files\MS USB Display\unins000.exe..;.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.M.S. .U.S.B. .D.i.s.p.l.a.y.\.u.n.i.n.s.0.0.0...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.M.S. .U.S.B. .D.i.s.p.l.a.y.`.......X.......651689..........N...n..O...}R...+.S.............N...n..O...}R...+.S.............E.......9...1SPS..mD..pH.H@..=x.....h....H....F.5./EG.gM.U..............
Process:C:\Users\user\Desktop\MSDisplay_MultiDev_v1.0.0.18.0.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):2633728
Entropy (8bit):6.411321473236685
Encrypted:false
SSDEEP:
MD5:7EC9CFAB450831249D70152183B3E844
SHA1:C98CF7641E799F17B784D74811DAC7600C4D4219
SHA-256:664938FC6169E37700C45C0242006EDE97219AA0B873CC26C8DAF19647DBAA77
SHA-512:DAC664E238B2251169E02C7BB939EC77E109B1CC211DF8B35ED3CB13A17339D1ACCBF7F9CC9E2450E8DA2800F4D1547BCF9B8525F953318AD31E5C542FCF4B4F
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 7%
  • Antivirus: Virustotal, Detection: 7%, Browse
Reputation:low
Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...L..\..................$..@........%.......%...@...........................)...........@......@...................@&.......%."6...p&.8....................................................`&.....................X.%.T....0&......................text.....$.......$................. ..`.itext...'....$..(....$............. ..`.data...T[....%..\....$.............@....bss.....u...p%..........................idata.."6....%..8...L%.............@....didata......0&.......%.............@....edata.......@&.......%.............@..@.tls....D....P&..........................rdata..]....`&.......%.............@..@.rsrc...8....p&.......%.............@..@..............'.......&.............@..@........................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:PE32+ executable (console) x86-64, for MS Windows
Category:dropped
Size (bytes):6144
Entropy (8bit):4.720366600008286
Encrypted:false
SSDEEP:
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:data
Category:dropped
Size (bytes):14685
Entropy (8bit):7.3568142147544195
Encrypted:false
SSDEEP:
MD5:63D0F690BF8C08AEE4EF2D4595A84EEF
SHA1:929B65C72C2C27C62280E8D94CD54BE19DCFD80C
SHA-256:97C85C8444C22FF6CC26214907BDAE7CE40F93879C35797D24C277168167FB35
SHA-512:14D3D62A812CEE0875EDA7F23A5DB5B3EEE335673203EA4BBD34EB69AD5C74F733DA7148D31D338B4C014E3B30A9512589C57E3E46416D7D1CE1DC39724DD8BE
Malicious:false
Reputation:low
Preview:0.9Y..*.H........9J0.9F...1.0...`.H.e......0..!..+.....7......0...0...+.....7......C.0.B>B....Uu....210512092504Z0...+.....7.....0...0....R1.6.5.4.6.0.E.2.0.2.8.2.F.8.A.5.F.1.A.7.3.D.F.1.9.4.5.2.C.F.E.4.5.0.6.4.2.1.8.F...1..=0:..+.....7...1,0*...F.i.l.e........l.i.b.u.s.b.0...d.l.l...0L..+.....7...1>0<...O.S.A.t.t.r.......&2.:.6...1.,.2.:.6...2.,.2.:.1.0...0...0M..+.....7...1?0=0...+.....7...0...........0!0...+.........T`......=.R..Pd!.0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0....R7.6.9.E.6.3.C.9.A.7.1.E.3.A.0.A.3.E.8.D.0.1.B.7.A.2.1.C.7.2.E.2.5.9.1.1.F.7.2.0...1..=0:..+.....7...1,0*...F.i.l.e........l.i.b.u.s.b.0...d.l.l...0L..+.....7...1>0<...O.S.A.t.t.r.......&2.:.6...1.,.2.:.6...2.,.2.:.1.0...0...0M..+.....7...1?0=0...+.....7...0...........0!0...+........v.c..:.>.....r.Y.. 0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0....R7.B.7.D.C.B.8.0.1.6.9.3.9.C.6.4.5.9.B.8.E.C
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:Windows setup INFormation
Category:dropped
Size (bytes):4303
Entropy (8bit):5.03850670649049
Encrypted:false
SSDEEP:
MD5:D2722501C5120B8B6FD785B397B8EF62
SHA1:7B7DCB8016939C6459B8EC51087860DCD99286B4
SHA-256:F853C3BAF49E4BA4FEB5D00681F85453C564261CD5C7CEE45D7D9BD350FEEDE6
SHA-512:AC57E72DD6AA89C8926241D9386F45E8E2FC4AF4BFF1B4438C7AA2B29E789BE882FAA54F1743E6E944079F80649983DD751C3533BD6975402ADC81431D78DE48
Malicious:false
Reputation:low
Preview:; MSUSBDisplay.inf.; Copyright (c) 2010 libusb (GNU LGPL).;.;--------------------------------------------------------------------------.; libusb-win32 (Strings).;--------------------------------------------------------------------------.[Strings].DeviceName = "MS USB2.0 Display".VendorName = "MS".SourceName = "MS USB2.0 Display Install Disk".DeviceID = "VID_534D&PID_6021&MI_03".DeviceGUID = "{73fc78a8-c15c-4955-accd-a73f3eba1639}"..;--------------------------------------------------------------------------.; libusb-win32 (Version / ClassInstall32 / Manufacturer).;--------------------------------------------------------------------------.[Version].Signature = "$Windows NT$".Class = "MS USB Display".ClassGUID = {EB781AAF-9C71-4523-A5DF-642A87ECA567}.Provider = %VendorName%.CatalogFile = MSUSBDisplay.cat.DriverVer = 03/22/2018, 1.0.0.0..[ClassInstall32].Addreg = libusb_class_install_add_reg..[libusb_class_install_add_reg].HKR,,,0,"MSUSBDisplay".HKR,,Icon,,-20..[Manufactur
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:data
Category:dropped
Size (bytes):14685
Entropy (8bit):7.3568142147544195
Encrypted:false
SSDEEP:
MD5:63D0F690BF8C08AEE4EF2D4595A84EEF
SHA1:929B65C72C2C27C62280E8D94CD54BE19DCFD80C
SHA-256:97C85C8444C22FF6CC26214907BDAE7CE40F93879C35797D24C277168167FB35
SHA-512:14D3D62A812CEE0875EDA7F23A5DB5B3EEE335673203EA4BBD34EB69AD5C74F733DA7148D31D338B4C014E3B30A9512589C57E3E46416D7D1CE1DC39724DD8BE
Malicious:false
Reputation:low
Preview:0.9Y..*.H........9J0.9F...1.0...`.H.e......0..!..+.....7......0...0...+.....7......C.0.B>B....Uu....210512092504Z0...+.....7.....0...0....R1.6.5.4.6.0.E.2.0.2.8.2.F.8.A.5.F.1.A.7.3.D.F.1.9.4.5.2.C.F.E.4.5.0.6.4.2.1.8.F...1..=0:..+.....7...1,0*...F.i.l.e........l.i.b.u.s.b.0...d.l.l...0L..+.....7...1>0<...O.S.A.t.t.r.......&2.:.6...1.,.2.:.6...2.,.2.:.1.0...0...0M..+.....7...1?0=0...+.....7...0...........0!0...+.........T`......=.R..Pd!.0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0....R7.6.9.E.6.3.C.9.A.7.1.E.3.A.0.A.3.E.8.D.0.1.B.7.A.2.1.C.7.2.E.2.5.9.1.1.F.7.2.0...1..=0:..+.....7...1,0*...F.i.l.e........l.i.b.u.s.b.0...d.l.l...0L..+.....7...1>0<...O.S.A.t.t.r.......&2.:.6...1.,.2.:.6...2.,.2.:.1.0...0...0M..+.....7...1?0=0...+.....7...0...........0!0...+........v.c..:.>.....r.Y.. 0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0....R7.B.7.D.C.B.8.0.1.6.9.3.9.C.6.4.5.9.B.8.E.C
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:Windows setup INFormation
Category:dropped
Size (bytes):4303
Entropy (8bit):5.03850670649049
Encrypted:false
SSDEEP:
MD5:D2722501C5120B8B6FD785B397B8EF62
SHA1:7B7DCB8016939C6459B8EC51087860DCD99286B4
SHA-256:F853C3BAF49E4BA4FEB5D00681F85453C564261CD5C7CEE45D7D9BD350FEEDE6
SHA-512:AC57E72DD6AA89C8926241D9386F45E8E2FC4AF4BFF1B4438C7AA2B29E789BE882FAA54F1743E6E944079F80649983DD751C3533BD6975402ADC81431D78DE48
Malicious:false
Reputation:low
Preview:; MSUSBDisplay.inf.; Copyright (c) 2010 libusb (GNU LGPL).;.;--------------------------------------------------------------------------.; libusb-win32 (Strings).;--------------------------------------------------------------------------.[Strings].DeviceName = "MS USB2.0 Display".VendorName = "MS".SourceName = "MS USB2.0 Display Install Disk".DeviceID = "VID_534D&PID_6021&MI_03".DeviceGUID = "{73fc78a8-c15c-4955-accd-a73f3eba1639}"..;--------------------------------------------------------------------------.; libusb-win32 (Version / ClassInstall32 / Manufacturer).;--------------------------------------------------------------------------.[Version].Signature = "$Windows NT$".Class = "MS USB Display".ClassGUID = {EB781AAF-9C71-4523-A5DF-642A87ECA567}.Provider = %VendorName%.CatalogFile = MSUSBDisplay.cat.DriverVer = 03/22/2018, 1.0.0.0..[ClassInstall32].Addreg = libusb_class_install_add_reg..[libusb_class_install_add_reg].HKR,,,0,"MSUSBDisplay".HKR,,Icon,,-20..[Manufactur
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):75200
Entropy (8bit):6.431338498790577
Encrypted:false
SSDEEP:
MD5:136FDF85FD90F166AF828CAD5D45CD99
SHA1:A61B25E71328388C5AF8954F29381B91A83467F2
SHA-256:FF5E4CC0FEA9EAF44BE4723868F28ABCC202B8283B4EEB424CD083866D7300D1
SHA-512:6E46EDA9149FBB0F726B355FD694EFA759C617805565F76106A219088FA909B9C4BE2ECDCBE60BA881D29D3CBBD274A5F376ED332192E373689CF52E7E00175F
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........u...&...&...&.0.&...&.k.&...&.k.&...&.k.&...&...&L..&.k.&...&.0.&...&.k.&...&.k.&...&.k.&...&.k.&...&.k.&...&Rich...&........................PE..d....X.L.........." ................l.........@..............................P......W.....@.............................................q............0....... ...............@.......................................................................................text...q........................... ..`.data...............................@....pdata....... ......................@..@.rsrc........0......................@..@.reloc..`....@......................@..B........................................................................................................................................................................................................................................................................
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):75200
Entropy (8bit):6.431338498790577
Encrypted:false
SSDEEP:
MD5:136FDF85FD90F166AF828CAD5D45CD99
SHA1:A61B25E71328388C5AF8954F29381B91A83467F2
SHA-256:FF5E4CC0FEA9EAF44BE4723868F28ABCC202B8283B4EEB424CD083866D7300D1
SHA-512:6E46EDA9149FBB0F726B355FD694EFA759C617805565F76106A219088FA909B9C4BE2ECDCBE60BA881D29D3CBBD274A5F376ED332192E373689CF52E7E00175F
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........u...&...&...&.0.&...&.k.&...&.k.&...&.k.&...&...&L..&.k.&...&.0.&...&.k.&...&.k.&...&.k.&...&.k.&...&.k.&...&Rich...&........................PE..d....X.L.........." ................l.........@..............................P......W.....@.............................................q............0....... ...............@.......................................................................................text...q........................... ..`.data...............................@....pdata....... ......................@..@.rsrc........0......................@..@.reloc..`....@......................@..B........................................................................................................................................................................................................................................................................
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):67008
Entropy (8bit):6.687793456659865
Encrypted:false
SSDEEP:
MD5:6C12D8B1AA5E44AF62EFAC5A5B25C6DA
SHA1:00B614AC1EB075BC529AFA56A086E8CDF05939A1
SHA-256:FA16629B7C112C2A22FAD27C2D5E5867866FD49E534F4A5161F97467C09698C3
SHA-512:BAC5F7276A3B06949ADC1A88502273E6E700639668FF86E4ADB6C4ABE47FA0A4946729BECF900E9724B2D0F7A1D28A5536A8F1DFD41576A232BA87B0A21675E1
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......l2&.(SH.(SH.(SH.qp[."SH...5./SH.(SI..SH...3.+SH...&.'SH...2.)SH...%.mSH...6.)SH...4.)SH...0.)SH.Rich(SH.................PE..L....X.L...........!........."....................@..................................4....@.........................`...q...L........................................................................6..@...............l............................text............................... ..`.data...$...........................@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):67008
Entropy (8bit):6.687793456659865
Encrypted:false
SSDEEP:
MD5:6C12D8B1AA5E44AF62EFAC5A5B25C6DA
SHA1:00B614AC1EB075BC529AFA56A086E8CDF05939A1
SHA-256:FA16629B7C112C2A22FAD27C2D5E5867866FD49E534F4A5161F97467C09698C3
SHA-512:BAC5F7276A3B06949ADC1A88502273E6E700639668FF86E4ADB6C4ABE47FA0A4946729BECF900E9724B2D0F7A1D28A5536A8F1DFD41576A232BA87B0A21675E1
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......l2&.(SH.(SH.(SH.qp[."SH...5./SH.(SI..SH...3.+SH...&.'SH...2.)SH...%.mSH...6.)SH...4.)SH...0.)SH.Rich(SH.................PE..L....X.L...........!........."....................@..................................4....@.........................`...q...L........................................................................6..@...............l............................text............................... ..`.data...$...........................@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\is-3SGKS.tmp\MSDisplay_MultiDev_v1.0.0.18.0.tmp
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Mar 30 14:14:40 2023, mtime=Thu Mar 30 14:14:42 2023, atime=Fri May 21 07:59:26 2021, length=1512448, window=hide
Category:dropped
Size (bytes):944
Entropy (8bit):4.533627794152751
Encrypted:false
SSDEEP:
MD5:38890DCC819E391FDCC5EB11D80EA6F8
SHA1:E780F61C3DC1D5720EFA415DE06C3B061873E17A
SHA-256:73CDFF235433B25680832ECDB7D5C2EA96AD185ED6BB2042BCFA656ADC98716B
SHA-512:44BE0E78E76DEF0767B0C44D6B0946F1C5E5466A8CB70519408C294512D0F32B4477F14E5FD56724BEF2A43844E5D2CB6A60A1DE9CFCCEBBA06211EBAD86FDF2
Malicious:false
Reputation:low
Preview:L..................F.... ...e..Y.c..,.vZ.c...+...N...............................P.O. .:i.....+00.../C:\.....................1.....~V.y..PROGRA~1..t......sN.&~V.y....B...............J......U..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....f.1.....~V.y..MSUSBD~1..N......~V.y~V.y.....X........................M.S. .U.S.B. .D.i.s.p.l.a.y.....p.2......RmG .WINUSB~1.EXE..T......~V.y~V.y.....b........................W.i.n.U.s.b.D.i.s.p.l.a.y...e.x.e.......`...............-......._...........7.I`.....C:\Program Files\MS USB Display\WinUsbDisplay.exe..C.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.M.S. .U.S.B. .D.i.s.p.l.a.y.\.W.i.n.U.s.b.D.i.s.p.l.a.y...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.M.S. .U.S.B. .D.i.s.p.l.a.y.`.......X.......651689..........N...n..O...}R.....S.............N...n..O...}R.....S.............E.......9...1SPS..mD..pH.H@..=x.....h....H....F.5./EG.gM.U..............
File Type:data
Category:dropped
Size (bytes):576
Entropy (8bit):5.059635826240281
Encrypted:false
SSDEEP:
MD5:FD0EF31614A6FC085134F1301106DD00
SHA1:C2D3C9CABC5E2CC4EE4B4DBC0FCB0E0F1BD3FDF5
SHA-256:DF6CB483EE9217FC57376CA74FA2EB34EE8E90D51AAE6C376114B7D0080B834C
SHA-512:02F2F1F88DDC5C271863DFCB717F127F0B8CE0CAF30B9531567D08831C1E42A765EBA25DF7BF1CD136CD9FAEFC70309F79908544AE72AA52F4D19088BB531BAA
Malicious:false
Reputation:low
Preview:.6...AAAAAAA...AAAAA...A.A.A/ALAAAAAAAAAAAbA5AtA.!.AGA.A.bbA.A`A.].A%A.A...A AHA...AVA.A.n.AKA.A6d.A.A.A6.A~AEA...6.A.A..Ab.A...A...A...An.LA..bA...A..bA..#A..bA5..A...6#.qA.^tA..&A.5.6..A..bA..A...6`.~A.G.6N..A..bA2..A...A6#.A.-.A.#.A...A.#cA...6*#.A.*bA..A...An..A...A..A..bA..A. bA..A.tbA.SAA.AbA.S.A.6.AF..A.L.A`..A...AN.A...A..(A.}.A...A.1.A...A..A...A...AV..A..AQ.yA._.AE.MA...A|.A...AU..A...6...A...6...A.?.6...A.H.A..A.9bAK.XA...A...A...A..DA..A...A.%bAZ.A.;b.q..A.#b...7A...Aw..A68.AAA.AtA.6...........................................................
Process:C:\Windows\System32\drvinst.exe
File Type:Windows Precompiled iNF, version 3.3 (Windows 10), flags 0x1000083, unicoded, has strings, at 0x1748 "Signature", at 0x68 WinDirPath
Category:dropped
Size (bytes):7716
Entropy (8bit):3.4489822560212957
Encrypted:false
SSDEEP:
MD5:6CEAEA33FCE6D6F6CF9F8FA4980D866A
SHA1:A5D858E53D561DBC4F02EA9B2A4087611072C7FF
SHA-256:AFE4ED85EB6DB63E4D63962AE7D3D5E62A7EA8195213D75695EF88869EB19499
SHA-512:7976BE8DF145B21A0AF621C60FCD92A94BE0C39CD96AE49EA40F71D0C94A5F2C2BB12B64657A259A1DA1B201A2AD15FEAEFD09878EAAEBB3874DB491CFF5F787
Malicious:false
Reputation:low
Preview:................2...H......f.c..........................,.......P...............h............... .......C.:.\.W.i.n.d.o.w.s.....0...................................................................................................P...............................................................................p...............\....................................................................................................................................................................... .......,...........................................................................4...............................................................................................................................T...................................H...........................................................`...................................................................@...d...............................................................................................................................
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:Generic INItialization configuration [BeginLog]
Category:dropped
Size (bytes):114716
Entropy (8bit):5.03669476262976
Encrypted:false
SSDEEP:
MD5:18212B03CA218DA87BAC12834E6499F7
SHA1:34277554EA6D232BAAD4D6612B1E0A77D7DE3456
SHA-256:1FADD5702C2E78AE51646FCD011481EACD1BFFAC0CFA4E7C7FF8B084CD72F3F6
SHA-512:43861D14C6E89802A75CC4B15ED5D5DCEF4A3AF5E17744B30471B47AE8ECD803D734478C8C53ABF15F914009CA4F1E93EBD73F903A357DD2C7C9FEFC8DCE2285
Malicious:false
Reputation:low
Preview:[Device Install Log].. OS Version = 10.0.18363.. Service Pack = 0.0.. Suite = 0x0100.. ProductType = 1.. Architecture = amd64....[BeginLog]....[Boot Session: 2021/05/27 07:15:46.500]....>>> [Setup Import Driver Package - C:\Windows\system32\spool\tools\Microsoft Print To PDF\prnms009.Inf]..>>> Section start 2021/05/27 07:18:03.852.. cmd: C:\Windows\System32\spoolsv.exe.. inf: Provider: Microsoft.. inf: Class GUID: {4D36E979-E325-11CE-BFC1-08002BE10318}.. inf: Driver Version: 06/21/2006,10.0.18362.1.. inf: Catalog File: prnms009.cat.. pol: {Driver package policy check} 07:18:03.883.. pol: {Driver package policy check - exit(0x00000000)} 07:18:03.883.. sto: {Stage Driver Package: C:\Windows\system32\spool\tools\Microsoft Print To PDF\prnms009.Inf} 07:18:03.915.. inf: {Query Configurability: C:\Windows\system32\spool\tools\Microsoft Print To PDF\prnms009.Inf} 07:18:03.915.. inf: Driver package 'prnms009.Inf' is
Process:C:\Windows\System32\drvinst.exe
File Type:Windows Precompiled iNF, version 3.3 (Windows 10), flags 0x1000083, unicoded, has strings, at 0x1748 "Signature", at 0x68 WinDirPath
Category:dropped
Size (bytes):7716
Entropy (8bit):3.4451266054924963
Encrypted:false
SSDEEP:
MD5:0B6A1FCD78CA6091840ED7366510A03E
SHA1:CA89FF393E287FD568179F4B209486823CBE677C
SHA-256:5447AADB92027DC73A21C1FB9C731648FFC2223C81BC732651A882A71802D5D0
SHA-512:4BAE6D4287CE9C638AA8CF35D8A4819BA353843916D04926DCB04BF6E7AB0DBB96B29EE4BA777C2637F63ABC569002207F3ECFB3195B1CB6B65B980FC3773201
Malicious:false
Reputation:low
Preview:................2...H........c..........................,.......P...............h............... .......C.:.\.W.i.n.d.o.w.s.....0...................................................................................................P...............................................................................p...............\....................................................................................................................................................................... .......,...........................................................................4...............................................................................................................................T...................................H...........................................................`...................................................................@...d...............................................................................................................................
Process:C:\Windows\System32\drvinst.exe
File Type:ASCII text, with CRLF line terminators
Category:modified
Size (bytes):184155
Entropy (8bit):5.362117920587437
Encrypted:false
SSDEEP:
MD5:73F02506AB9EC95AEAB1DB8713966884
SHA1:FB7CACD1876B352F53D19F2621792580C0C1F421
SHA-256:949185540CD0FBA5D9C10282F2A2B69FD3073F7BE4D1BFB691D726867DB95435
SHA-512:33573F60A36F64C5D1FF28A54FBEA5669A502DFAFFC2D14F82DA890C0F9034DD32D0C04996C8D3B404225C442EA40EC3B24F86E94A07BA925C4A7F8D20D300BC
Malicious:false
Reputation:low
Preview:CatalogDB: 7:15:57 AM 5/27/2021: SyncDB:: DeleteCatalog: Containers-ApplicationGuard-Package~31bf3856ad364e35~amd64~~10.0.18362.1.cat..CatalogDB: 7:15:59 AM 5/27/2021: SyncDB:: DeleteCatalog: Containers-ApplicationGuard-Shared-Package~31bf3856ad364e35~amd64~~10.0.18362.1.cat..CatalogDB: 7:15:59 AM 5/27/2021: SyncDB:: DeleteCatalog: Containers-ApplicationGuard-Shared-windows-Package~31bf3856ad364e35~amd64~~10.0.18362.1.cat..CatalogDB: 7:15:59 AM 5/27/2021: SyncDB:: DeleteCatalog: Containers-Client-Manager-onecore-Package~31bf3856ad364e35~amd64~~10.0.18362.1.cat..CatalogDB: 7:15:59 AM 5/27/2021: catdbsvc.cpp at line #1470 encountered error 0x0000012f..CatalogDB: 7:15:59 AM 5/27/2021: catdbsvc.cpp at line #2046 encountered error 0x0000012f..CatalogDB: 7:15:59 AM 5/27/2021: catdbsvc.cpp at line #2359 encountered error 0x0000012f..CatalogDB: 7:15:59 AM 5/27/2021: catdbsvc.cpp at line #1245 encountered JET error -1601..CatalogDB: 7:15:59 AM 5/27/2021: catdbsvc.cpp at line #1245 encounter
Process:C:\Program Files\MS USB Display\tool\x64\devcon.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):106
Entropy (8bit):5.245866208871976
Encrypted:false
SSDEEP:
MD5:27EE96FEB535F35CA4600D62E6B02B76
SHA1:3947D9E29011F05EC48142C5E78C719C82EC60BF
SHA-256:F45D120C70DA41F0C152A69502F033D6DC0FEE02C923BCC35D230EA3CA1ED71E
SHA-512:8DF41F5266782E73B26CE3498309C1E0C0CBA0C66A329114E2921C24C3E588FEE81FD76210C97A19A45B4C0351ED86F90B020B2A35A4C40BBF2ED37E000ACBCB
Malicious:false
Reputation:low
Preview:PCI\VEN_8086&DEV_0405&SUBSYS_040515AD&REV_00\3&61AAA01&0&78 : Restart failed..No matching devices found...
File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.819497671904101
TrID:
  • Win32 Executable (generic) a (10002005/4) 98.04%
  • Inno Setup installer (109748/4) 1.08%
  • InstallShield setup (43055/19) 0.42%
  • Win32 EXE PECompact compressed (generic) (41571/9) 0.41%
  • Win16/32 Executable Delphi generic (2074/23) 0.02%
File name:MSDisplay_MultiDev_v1.0.0.18.0.exe
File size:3275933
MD5:f505cbcab0670a376c866de177a5c097
SHA1:18ded789bc554fda5941aa2707df9a78de44c7c5
SHA256:7be04791df7cc79fc8427098bf9e3c11206e54d2d613d470e4b4d5855451e816
SHA512:d1214d5188315466105713e509e8ba777eb9e89ba6fbfc5a0244314cd6607f6c1f7d265f468daba0114a9116ec4d480c515897d9288f2c9c304efc3637f0074e
SSDEEP:49152:jNJb0uRDKiHjoapN8J827nsjoRf8HIjkpr6PbdVKeO3dFIyKc+Kq:joKDfD4827MoRf8HnUdyd+yKn
TLSH:0AE5F12BB148653EC46D2A364773A150797BAA51F416BF2772F0DA0DCF3A1C01E3AE16
File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
Icon Hash:a2365a4961b2b0b0
Entrypoint:0x4a6ed0
Entrypoint Section:.itext
Digitally signed:false
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x5CC7C54B [Tue Apr 30 03:47:23 2019 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:eb5bc6ff6263b364dfbfb78bdb48ed59
Instruction
push ebp
mov ebp, esp
add esp, FFFFFFA4h
push ebx
push esi
push edi
xor eax, eax
mov dword ptr [ebp-3Ch], eax
mov dword ptr [ebp-40h], eax
mov dword ptr [ebp-5Ch], eax
mov dword ptr [ebp-30h], eax
mov dword ptr [ebp-38h], eax
mov dword ptr [ebp-34h], eax
mov dword ptr [ebp-2Ch], eax
mov dword ptr [ebp-28h], eax
mov dword ptr [ebp-14h], eax
mov eax, 004A2278h
call 00007F6D1C2940BDh
xor eax, eax
push ebp
push 004A75C2h
push dword ptr fs:[eax]
mov dword ptr fs:[eax], esp
xor edx, edx
push ebp
push 004A757Eh
push dword ptr fs:[edx]
mov dword ptr fs:[edx], esp
mov eax, dword ptr [004AF634h]
call 00007F6D1C328077h
call 00007F6D1C327C36h
lea edx, dword ptr [ebp-14h]
xor eax, eax
call 00007F6D1C2A96E8h
mov edx, dword ptr [ebp-14h]
mov eax, 004B2708h
call 00007F6D1C28E947h
push 00000002h
push 00000000h
push 00000001h
mov ecx, dword ptr [004B2708h]
mov dl, 01h
mov eax, dword ptr [00423698h]
call 00007F6D1C2AA747h
mov dword ptr [004B270Ch], eax
xor edx, edx
push ebp
push 004A752Ah
push dword ptr fs:[edx]
mov dword ptr fs:[edx], esp
call 00007F6D1C3280FFh
mov dword ptr [004B2714h], eax
mov eax, dword ptr [004B2714h]
cmp dword ptr [eax+0Ch], 01h
jne 00007F6D1C32DAFAh
mov eax, dword ptr [004B2714h]
mov edx, 00000028h
call 00007F6D1C2AB03Ch
mov edx, dword ptr [004B2714h]
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0xb50000x9a.edata
IMAGE_DIRECTORY_ENTRY_IMPORT0xb30000xf1c.idata
IMAGE_DIRECTORY_ENTRY_RESOURCE0xb80000x19dc4.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0xb70000x18.rdata
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0xb32e00x240.idata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xb40000x1a4.didata
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000xa47a00xa4800False0.35706568199088146data6.3889818358526504IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.itext0xa60000x16680x1800False0.5400390625data5.901230511226496IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.data0xa80000x37a40x3800False0.36083984375data5.046702820762568IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.bss0xac0000x676c0x0False0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.idata0xb30000xf1c0x1000False0.366455078125data4.879899770580934IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.didata0xb40000x1a40x200False0.345703125data2.712872162409855IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.edata0xb50000x9a0x200False0.2578125data1.8895623989294017IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.tls0xb60000x180x0False0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rdata0xb70000x5d0x200False0.189453125data1.3824199855691357IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0xb80000x19dc40x19e00False0.20505925422705315data5.5005810458446724IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountry
RT_ICON0xb85e80x668Device independent bitmap graphic, 48 x 96 x 4, image size 1152ChineseChina
RT_ICON0xb8c500x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512ChineseChina
RT_ICON0xb8f380x128Device independent bitmap graphic, 16 x 32 x 4, image size 128ChineseChina
RT_ICON0xb90600xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsChineseChina
RT_ICON0xb9f080x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsChineseChina
RT_ICON0xba7b00x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsChineseChina
RT_ICON0xbad180x10828Device independent bitmap graphic, 128 x 256 x 32, image size 67584ChineseChina
RT_ICON0xcb5400x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600ChineseChina
RT_ICON0xcdae80x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224ChineseChina
RT_ICON0xceb900x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088ChineseChina
RT_STRING0xceff80x360data
RT_STRING0xcf3580x260data
RT_STRING0xcf5b80x45cdata
RT_STRING0xcfa140x40cdata
RT_STRING0xcfe200x2d4data
RT_STRING0xd00f40xb8data
RT_STRING0xd01ac0x9cdata
RT_STRING0xd02480x374data
RT_STRING0xd05bc0x398data
RT_STRING0xd09540x368data
RT_STRING0xd0cbc0x2a4data
RT_RCDATA0xd0f600x10data
RT_RCDATA0xd0f700x2c4data
RT_RCDATA0xd12340x2cdata
RT_GROUP_ICON0xd12600x92dataChineseChina
RT_VERSION0xd12f40x52cdataChineseChina
RT_MANIFEST0xd18200x5a4XML 1.0 document, ASCII text, with CRLF line terminatorsChineseChina
DLLImport
kernel32.dllGetACP, GetExitCodeProcess, LocalFree, CloseHandle, SizeofResource, VirtualProtect, VirtualFree, GetFullPathNameW, ExitProcess, HeapAlloc, GetCPInfoExW, RtlUnwind, GetCPInfo, GetStdHandle, GetModuleHandleW, FreeLibrary, HeapDestroy, ReadFile, CreateProcessW, GetLastError, GetModuleFileNameW, SetLastError, FindResourceW, CreateThread, CompareStringW, LoadLibraryA, ResetEvent, GetVersion, RaiseException, FormatMessageW, SwitchToThread, GetExitCodeThread, GetCurrentThread, LoadLibraryExW, LockResource, GetCurrentThreadId, UnhandledExceptionFilter, VirtualQuery, VirtualQueryEx, Sleep, EnterCriticalSection, SetFilePointer, LoadResource, SuspendThread, GetTickCount, GetFileSize, GetStartupInfoW, GetFileAttributesW, InitializeCriticalSection, GetThreadPriority, SetThreadPriority, GetCurrentProcess, VirtualAlloc, GetSystemInfo, GetCommandLineW, LeaveCriticalSection, GetProcAddress, ResumeThread, GetVersionExW, VerifyVersionInfoW, HeapCreate, GetWindowsDirectoryW, VerSetConditionMask, GetDiskFreeSpaceW, FindFirstFileW, GetUserDefaultUILanguage, lstrlenW, QueryPerformanceCounter, SetEndOfFile, HeapFree, WideCharToMultiByte, FindClose, MultiByteToWideChar, LoadLibraryW, SetEvent, CreateFileW, GetLocaleInfoW, GetSystemDirectoryW, DeleteFileW, GetLocalTime, GetEnvironmentVariableW, WaitForSingleObject, WriteFile, ExitThread, DeleteCriticalSection, TlsGetValue, GetDateFormatW, SetErrorMode, IsValidLocale, TlsSetValue, CreateDirectoryW, GetSystemDefaultUILanguage, EnumCalendarInfoW, LocalAlloc, GetUserDefaultLangID, RemoveDirectoryW, CreateEventW, SetThreadLocale, GetThreadLocale
comctl32.dllInitCommonControls
version.dllGetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
user32.dllCreateWindowExW, TranslateMessage, CharLowerBuffW, CallWindowProcW, CharUpperW, PeekMessageW, GetSystemMetrics, SetWindowLongW, MessageBoxW, DestroyWindow, CharNextW, MsgWaitForMultipleObjects, LoadStringW, ExitWindowsEx, DispatchMessageW
oleaut32.dllSysAllocStringLen, SafeArrayPtrOfIndex, VariantCopy, SafeArrayGetLBound, SafeArrayGetUBound, VariantInit, VariantClear, SysFreeString, SysReAllocStringLen, VariantChangeType, SafeArrayCreate
netapi32.dllNetWkstaGetInfo, NetApiBufferFree
advapi32.dllRegQueryValueExW, AdjustTokenPrivileges, LookupPrivilegeValueW, RegCloseKey, OpenProcessToken, RegOpenKeyExW
NameOrdinalAddress
TMethodImplementationIntercept30x4539cc
__dbk_fcall_wrapper20x40d3dc
dbkFCallWrapperAddr10x4af63c
Language of compilation systemCountry where language is spokenMap
ChineseChina