Loading ...

Play interactive tourEdit tour

Analysis Report CID_x64.msi


General Information

Sample Name:CID_x64.msi
Analysis ID:324348

Most interesting Screenshot:


Range:0 - 100


Checks for available system drives (often done to infect USB drives)
Drops PE files
Found dropped PE file which has not been started or loaded
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Tries to load missing DLLs


Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample is looking for USB drives. Launch the sample with the USB Fake Disk cookbook
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior


  • System is w10x64
  • msiexec.exe (PID: 4020 cmdline: 'C:\Windows\System32\msiexec.exe' /i 'C:\Users\user\Desktop\CID_x64.msi' MD5: 4767B71A318E201188A0D0A420C8B608)
  • msiexec.exe (PID: 5056 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 7C2160B8C719111621BBF907BA5D9B1C C MD5: 12C17B5A5C2A7B97342C362CA467E9A2)
  • msiexec.exe (PID: 5364 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 67B6CF52D8EDBBB744EA0BA0249B0181 MD5: 12C17B5A5C2A7B97342C362CA467E9A2)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmpString found in binary or memory: http://crl.globals
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmp, CID_x64.msiString found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmp, CID_x64.msiString found in binary or memory: http://crl.globalsign.com/gsextendcodesignsha2g3.crl0
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmp, CID_x64.msiString found in binary or memory: http://crl.globalsign.com/root-r3.crl0b
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: msiexec.exe, 00000000.00000002.469784631.0000023764110000.00000004.00000001.sdmp, CID_x64.msiString found in binary or memory: http://crl.globalsign.net/root-r3.crl0
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmpString found in binary or memory: http://ocsp2.globalsign.com/g
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmp, CID_x64.msiString found in binary or memory: http://ocsp2.globalsign.com/gsextendcodesignsha2g30U
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmp, CID_x64.msiString found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20
Source: CID_x64.msiString found in binary or memory: http://ocsp2.globalsign.com/rootr306
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmpString found in binary or memory: http://secure.globalsign.com/cacert/gsextendcodesignsha2g3oc
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmp, CID_x64.msiString found in binary or memory: http://secure.globalsign.com/cacert/gsextendcodesignsha2g3ocsp.crt0
Source: msiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmp, CID_x64.msiString found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0
Source: CID_x64.msiString found in binary or memory: https://www.globalsign.com/repository/0
Source: msiexec.exe, 00000000.00000002.469784631.0000023764110000.00000004.00000001.sdmp, CID_x64.msiString found in binary or memory: https://www.globalsign.com/repository/06
Source: CID_x64.msiBinary or memory string: OriginalFilenameDPCA.DLL^ vs CID_x64.msi
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: classification engineClassification label: clean3.winMSI@3/4@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\MSI5735.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: msiexec.exe, 00000000.00000002.470111091.0000023764710000.00000002.00000001.sdmpBinary or memory string: SELECT `Directory`, `DefaultDir` FROM `Directory` WHERE `Directory_Parent` = '%s'Software\Microsoft\NET Framework Setup\NDP\v3.%lu%sSOFTWARE\Microsoft\NET Framework Setup\DotNetClient\v3.5Software\Microsoft\NET Framework Setup\NDPSELECT * FROM `%s`Custom action not implemented.ToggleNearestAppRoot.kernel32IsWow64ProcessProcess call was successful.The error indicates that IIS is in 64 bit mode, while this application is a 32 bit application and thus not compatible.The error indicates that IIS is in 32 bit mode, while this application is a 64 bit application and thus not compatible.The error indicates that this version of ASP.NET must first be registered on the machine.Unknown Error.The call to aspnet_regiis.exe was failed. Path: '%s'Process Call Result Code: '%ld'Process Exit Code: '%ld'.Create Process failed.Running process '%s' with parameters '%s' silently...Access denied.CoInitializeEx - COM initialization Free Threaded.FAILED:%ldCoInitializeEx - COM initialization Apartment Threaded...Attach Debugger To MeVSCADEBUGATTACHSetTARGETSITETargetVersion%s\v%d\%sGatherWebSitesGatherAppPoolsSetTARGETAPPPOOLTARGETIISPATHRoot//LM/TARGETVDIRTARGETSITESetTARGETIISPATHaspnet_regiis.exeRESULTPath = PathUsing 64 bit registry key...Reading registry value Path from key 'HKLM\%s'...Software\Microsoft\ASP.NET\%sProductNameRunning show message with fUseMessageBox = %sFALSETRUEVSDINVALIDURLMSGHideFatalErrorFormopenExecuting URL '%s' with source directory '%s'...SourceDirRESULT:Condition is false.RESULT:Condition is true. Nothing more to do.Evaluating condition '%s'...Getting the condition to evaluate...A launch condition has already fired. My work is done here.Checking a launch condition..."/><supportedRuntime version=";VSDFxConfigFile
Source: CID_x64.msiStatic file information: TRID: Microsoft Windows Installer (77509/1) 90.64%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe 'C:\Windows\System32\msiexec.exe' /i 'C:\Users\user\Desktop\CID_x64.msi'
Source: unknownProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 7C2160B8C719111621BBF907BA5D9B1C C
Source: unknownProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 67B6CF52D8EDBBB744EA0BA0249B0181
Source: C:\Windows\SysWOW64\msiexec.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32Jump to behavior
Source: CID_x64.msiStatic PE information: certificate valid
Source: CID_x64.msiStatic file information: File size 2429952 > 1048576
Source: Binary string: DPCA.pdb source: msiexec.exe, 00000000.00000002.470111091.0000023764710000.00000002.00000001.sdmp, CID_x64.msi
Source: Binary string: DPCA.pdb<0 source: msiexec.exe, 00000000.00000002.470111091.0000023764710000.00000002.00000001.sdmp, CID_x64.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\MSI5735.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\MSI58FB.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeRegistry key monitored for changes: HKEY_CURRENT_USER_ClassesJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI58FB.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: msiexec.exe, 00000000.00000002.468247204.0000023761FD0000.00000002.00000001.sdmp, msiexec.exe, 00000001.00000002.468238994.0000000002D80000.00000002.00000001.sdmpBinary or memory string: Program Manager
Source: msiexec.exe, 00000000.00000002.468247204.0000023761FD0000.00000002.00000001.sdmp, msiexec.exe, 00000001.00000002.468238994.0000000002D80000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
Source: msiexec.exe, 00000000.00000002.468247204.0000023761FD0000.00000002.00000001.sdmp, msiexec.exe, 00000001.00000002.468238994.0000000002D80000.00000002.00000001.sdmpBinary or memory string: Progman
Source: msiexec.exe, 00000000.00000002.468247204.0000023761FD0000.00000002.00000001.sdmp, msiexec.exe, 00000001.00000002.468238994.0000000002D80000.00000002.00000001.sdmpBinary or memory string: Progmanlock
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Replication Through Removable Media1Windows Management InstrumentationDLL Side-Loading1Process Injection2Process Injection2OS Credential DumpingQuery Registry1Replication Through Removable Media1Data from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsDLL Side-Loading1DLL Side-Loading1LSASS MemoryProcess Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerPeripheral Device Discovery11SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Information Discovery13Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud

Behavior Graph

Hide Legend


  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 324348 Sample: CID_x64.msi Startdate: 29/11/2020 Architecture: WINDOWS Score: 3 4 msiexec.exe 5 2->4         started        7 msiexec.exe 1 2->7         started        9 msiexec.exe 1 2->9         started        file3 11 C:\Users\user\AppData\Local\...\MSI58FB.tmp, PE32 4->11 dropped 13 C:\Users\user\AppData\Local\...\MSI5735.tmp, PE32 4->13 dropped



This section contains all screenshots as thumbnails, including those not shown in the slideshow.


Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample


Dropped Files


Unpacked PE Files

No Antivirus matches


No Antivirus matches


http://crl.globals0%Avira URL Cloudsafe

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
http://crl.globalsmsiexec.exe, 00000000.00000002.467504090.0000023761AD0000.00000004.00000020.sdmpfalse
  • Avira URL Cloud: safe

Contacted IPs

No contacted IP infos

General Information

Joe Sandbox Version:31.0.0 Red Diamond
Analysis ID:324348
Start date:29.11.2020
Start time:12:21:44
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:CID_x64.msi
Cookbook file name:default.jbs
Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
Number of analysed new started processes analysed:22
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
  • HCA enabled
  • EGA enabled
  • HDC enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
EGA Information:Failed
HDC Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Adjust boot time
  • Enable AMSI
  • Found application associated with file extension: .msi
Show All
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.


Behavior and APIs

No simulations

Joe Sandbox View / Context


No context


No context


No context

JA3 Fingerprints

No context

Dropped Files

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
C:\Users\user\AppData\Local\Temp\MSI58FB.tmpgRF9gjcjua.exeGet hashmaliciousBrowse
    C:\Users\user\AppData\Local\Temp\MSI5735.tmpgRF9gjcjua.exeGet hashmaliciousBrowse

      Created / dropped Files

      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Size (bytes):117
      Entropy (8bit):4.772296691735276
      Reputation:moderate, very likely benign file
      Preview: <?xml version="1.0"?>..<configuration>...<startup><supportedRuntime version="v4.0"/>...</startup>..</configuration>..
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Size (bytes):117
      Entropy (8bit):4.772296691735276
      Reputation:moderate, very likely benign file
      Preview: <?xml version="1.0"?>..<configuration>...<startup><supportedRuntime version="v4.0"/>...</startup>..</configuration>..
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Size (bytes):236872
      Entropy (8bit):6.42500790517661
      • Antivirus: Virustotal, Detection: 0%, Browse
      • Antivirus: Metadefender, Detection: 0%, Browse
      • Antivirus: ReversingLabs, Detection: 0%
      Joe Sandbox View:
      • Filename: gRF9gjcjua.exe, Detection: malicious, Browse
      Reputation:moderate, very likely benign file
      Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......S/...N...N...N..0....N..p8E..N...6l..N..x8D.+N..x8q..N..x8E.N...6|..N...N..FO..p8D..N..p8t..N..p8u..N..p8r..N..Rich.N..........PE..L......K.........."!..... ..........~........0.....A.................................U....@..........................,..#...D ..........8...............H........ ......................................@............................................text............ .................. ..`.data....H...0.......$..............@....rsrc...8............>..............@..@.reloc...@.......B...D..............@..B................................................................................................................................................................................................................................................................................................................................................
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Size (bytes):236872
      Entropy (8bit):6.42500790517661
      • Antivirus: Virustotal, Detection: 0%, Browse
      • Antivirus: Metadefender, Detection: 0%, Browse
      • Antivirus: ReversingLabs, Detection: 0%
      Joe Sandbox View:
      • Filename: gRF9gjcjua.exe, Detection: malicious, Browse
      Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......S/...N...N...N..0....N..p8E..N...6l..N..x8D.+N..x8q..N..x8E.N...6|..N...N..FO..p8D..N..p8t..N..p8u..N..p8r..N..Rich.N..........PE..L......K.........."!..... ..........~........0.....A.................................U....@..........................,..#...D ..........8...............H........ ......................................@............................................text............ .................. ..`.data....H...0.......$..............@....rsrc...8............>..............@..@.reloc...@.......B...D..............@..B................................................................................................................................................................................................................................................................................................................................................

      Static File Info


      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: x64;1033, Number of Pages: 200, Revision Number: {ED3668BC-F332-48C8-A8C2-23BD2F353508}, Title: CID, Author: ILANTUS Technologies, Number of Words: 2, Last Saved Time/Date: Wed Oct 7 06:41:24 2020, Last Printed: Wed Oct 7 06:41:24 2020
      Entropy (8bit):7.791882250085863
      • Microsoft Windows Installer (77509/1) 90.64%
      • Generic OLE2 / Multistream Compound File (8008/1) 9.36%
      File name:CID_x64.msi
      File size:2429952
      File Content Preview:........................>...................&...............8...................e...f...g...h...........[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...{..............................

      File Icon

      Icon Hash:a2a0b496b2caca72

      Static OLE Info


      Document Type:OLE
      Number of OLE Files:1

      Authenticode Signature

      Signature Valid:true
      Signature Issuer:CN=GlobalSign Extended Validation CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE
      Signature Validation Error:The operation completed successfully
      Error Number:0
      Not Before, Not After
      • 9/13/2019 7:03:54 AM 12/27/2020 1:49:30 AM
      Subject Chain
      • CN=Ilantus Technologies Private Limited, O=Ilantus Technologies Private Limited, STREET="Novel Business Park, 57, 13th Cross Gajendra Nagar Baldwin's College road", L=Bengaluru, S=Karnataka, C=IN, OID., OID., SERIALNUMBER=U72900KA2000PTC027338, OID. Organization
      Thumbprint MD5:2ACE4A9B419194C685C3E4EAC8705A05
      Thumbprint SHA-1:480B2FFCB5C94B0D92740AB9880F610CA87E11BE
      Thumbprint SHA-256:FD01E3DABB5F2C95F74976F26BF32CD49FC4378BE49DAF50C3381CB90FFFA9BB

      OLE File "CID_x64.msi"


      Has Summary Info:True
      Application Name:Windows Installer
      Encrypted Document:True
      Contains Word Document Stream:False
      Contains Workbook/Book Stream:False
      Contains PowerPoint Document Stream:False
      Contains Visio Document Stream:False
      Contains ObjectPool Stream:
      Flash Objects Count:
      Contains VBA Macros:False


      Code Page:1252
      Author:ILANTUS Technologies
      Revion Number:{ED3668BC-F332-48C8-A8C2-23BD2F353508}
      Last Printed:2020-10-07 05:41:24.343000
      Create Time:1999-06-21 07:00:00
      Last Saved Time:2020-10-07 05:41:24.343000
      Number of Pages:200
      Number of Words:2
      Creating Application:Windows Installer


      Stream Path: \x5DigitalSignature, File Type: data, Stream Size: 6655
      Stream Path:\x5DigitalSignature
      File Type:data
      Stream Size:6655
      Base64 Encoded:True
      Data ASCII:0 . . . . . * . H . . . . . . . . . . 0 . . . . . . 1 . 0 . . . + . . . . . . 0 g . . + . . . . . 7 . . . . Y 0 W 0 2 . . + . . . . . 7 . . . 0 $ . . . . . . . . . . . . . . . . . . . . F . . . . . . . . . . . . . . . 0 ! 0 . . . + . . . . . . . . 6 q R r ` C . Y . y . . . < | . d Z . . . . . . 0 . . . 0 . . . . . . . . . . H . j . . B L . . . . . . . 0 . . . * . H . . . . . . . . 0 L 1 0 . . . U . . . . G l o b a l S i g n R o o t C A - R 3 1 . 0 . . . U . . . . G l o b a l S i g n 1 . 0 . . . U
      Data Raw:30 82 19 fb 06 09 2a 86 48 86 f7 0d 01 07 02 a0 82 19 ec 30 82 19 e8 02 01 01 31 0b 30 09 06 05 2b 0e 03 02 1a 05 00 30 67 06 0a 2b 06 01 04 01 82 37 02 01 04 a0 59 30 57 30 32 06 0a 2b 06 01 04 01 82 37 02 01 1e 30 24 02 01 02 04 10 f1 10 0c 00 00 00 00 00 c0 00 00 00 00 00 00 46 02 01 00 02 01 00 02 01 00 02 01 00 02 01 00 30 21 30 09 06 05 2b 0e 03 02 1a 05 00 04 14 36 71 52 72
      Stream Path: \x5MsiDigitalSignatureEx, File Type: data, Stream Size: 20
      Stream Path:\x5MsiDigitalSignatureEx
      File Type:data
      Stream Size:20
      Base64 Encoded:False
      Data ASCII:. t p . . . . . 3 . . . _ . . : W b < .
      Data Raw:19 74 70 e8 e9 a0 e5 c6 33 a7 ab bb 5f e2 9a 3a 57 62 3c 00
      Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 420
      Stream Path:\x5SummaryInformation
      File Type:data
      Stream Size:420
      Base64 Encoded:True
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . < . . . . . . . H . . . . . . . T . . . . . . . \\ . . . . . . . h . . . @ . . . . . . . . . . . . . . . . . . . W i n d o w s I n s t a l l e r . . . . . . . . . . . . . . . . . . . . . . . . . . . x 6 4 ; 1 0 3 3 . . . . . . . .
      Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 74 01 00 00 0f 00 00 00 0c 00 00 00 80 00 00 00 12 00 00 00 8c 00 00 00 13 00 00 00 a8 00 00 00 01 00 00 00 b0 00 00 00 07 00 00 00 b8 00 00 00 0e 00 00 00 cc 00 00 00 09 00 00 00 d4 00 00 00 02 00 00 00 04 01 00 00 03 00 00 00 10 01 00 00
      Stream Path: \x15295\x15047\x14734\x14471\x15049\x14988\x15119\x14470\x15109\x14464\x15181\x14404\x15301\x15113\x14468\x15108\x18444, File Type: Microsoft Cabinet archive data, 1966548 bytes, 5 files, Stream Size: 1966548
      Stream Path:\x15295\x15047\x14734\x14471\x15049\x14988\x15119\x14470\x15109\x14464\x15181\x14404\x15301\x15113\x14468\x15108\x18444
      File Type:Microsoft Cabinet archive data, 1966548 bytes, 5 files
      Stream Size:1966548
      Base64 Encoded:True
      Data ASCII:M S C F . . . . . . . . . . . . D . . . . . . . . . . . . . . . . . . . > . . . . . . . . . . . . . . . } . . . . . . . . O . . . . . . . [ . . . . . . . . G Q @ Y . . _ 5 8 D 6 4 B 7 3 A C B 7 4 9 E D 8 D 4 3 4 F 8 E B E E F 7 A 4 5 . ; . . . . . . . . . G Q k Y . . _ 7 3 2 C F 1 9 C 6 1 4 A 4 3 5 6 9 C E 4 6 A C 4 C A A 4 3 A 5 8 . . . . . ; . . . . . G Q k Y . . _ C B C 9 3 D 7 2 4 8 3 B 4 1 9 8 8 5 7 D C E 4 A C D 8 C 6 6 7 A . . . . . . . . . . . G Q k Y . . _ D 7 8 6 6 8 2 7 2 0 0 4 4 C 2 C A 6 9 D E
      Data Raw:4d 53 43 46 00 00 00 00 d4 01 1e 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 04 00 05 00 00 00 00 00 00 00 3e 01 00 00 1d 00 01 00 0b b2 07 00 1c 00 01 00 7d 01 0f 00 1c 00 01 00 fa 4f 16 00 1d 00 01 00 f0 5b 0e 00 00 00 00 00 00 00 47 51 40 59 00 00 5f 35 38 44 36 34 42 37 33 41 43 42 37 34 39 45 44 38 44 34 33 34 46 38 45 42 45 45 46 37 41 34 35 00 3b 01 00 00 00 00 00 00 01 00
      Stream Path: \x17163\x16689\x18229\x15230\x17000\x16651\x17521\x17768\x17163\x17463\x17636, File Type: PC bitmap, Windows 3.x format, 500 x 70 x 24, Stream Size: 105056
      Stream Path:\x17163\x16689\x18229\x15230\x17000\x16651\x17521\x17768\x17163\x17463\x17636
      File Type:PC bitmap, Windows 3.x format, 500 x 70 x 24
      Stream Size:105056
      Base64 Encoded:False
      Data ASCII:B M ` . . . . . . . 6 . . . ( . . . . . . . F . . . . . . . . . . . * . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:42 4d 60 9a 01 00 00 00 00 00 36 00 00 00 28 00 00 00 f4 01 00 00 46 00 00 00 01 00 18 00 00 00 00 00 2a 9a 01 00 12 0b 00 00 12 0b 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
      Stream Path: \x17163\x16689\x18229\x15806\x16348\x15179\x15129\x15178\x15701, File Type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, Stream Size: 236872
      Stream Path:\x17163\x16689\x18229\x15806\x16348\x15179\x15129\x15178\x15701
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Stream Size:236872
      Base64 Encoded:True
      Data ASCII:M Z . . . . . . . . . . . . . . . . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . L . ! T h i s p r o g r a m c a n n o t b e r u n i n D O S m o d e . . . . $ . . . . . . . S / . . . N . . . N . . . N . . 0 . . . . N . . p 8 E . . N . . . 6 l . . N . . x 8 D . + N . . x 8 q . . N . . x 8 E . . N . . . 6 | . . N . . . N . . F O . . p 8 D . . N . . p 8 t . . N . . p 8 u . . N . . p 8 r . . N . . R i c h . N . . . . . . . . . .
      Data Raw:4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00
      Stream Path: \x17163\x16689\x18229\x15870\x18088\x17359\x17767\x17867\x18481, File Type: MS Windows icon resource - 1 icon, 16x16, 16 colors, Stream Size: 318
      Stream Path:\x17163\x16689\x18229\x15870\x18088\x17359\x17767\x17867\x18481
      File Type:MS Windows icon resource - 1 icon, 16x16, 16 colors
      Stream Size:318
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . ( . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . { { { { { . . . . . . . . . . . { { { { { . . . . . . . . . . . { { { { { . . . . . . . . . . . p { { { { . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:00 00 01 00 01 00 10 10 10 00 00 00 00 00 28 01 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 04 00 00 00 00 00 c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 00 00 ff 00 ff 00 ff ff 00 00 ff ff ff 00 00 00
      Stream Path: \x17163\x16689\x18229\x16318\x15347\x16879\x15093\x17527, File Type: MS Windows icon resource - 1 icon, 16x16, 16 colors, Stream Size: 318
      Stream Path:\x17163\x16689\x18229\x16318\x15347\x16879\x15093\x17527
      File Type:MS Windows icon resource - 1 icon, 16x16, 16 colors
      Stream Size:318
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . ( . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . { { { { { . . . . . . . . . . . { . { { { . . . . . . . . . . . . . . { { . . . . . . . . . . . { . { { { . . . . . . . . . . { { { x . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:00 00 01 00 01 00 10 10 10 00 00 00 00 00 28 01 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 04 00 00 00 00 00 c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 00 00 ff 00 ff 00 ff ff 00 00 ff ff ff 00 00 00
      Stream Path: \x17163\x16689\x18229\x16382\x15196\x15255\x15133\x15375, File Type: XML 1.0 document, ASCII text, with CRLF line terminators, Stream Size: 11247
      Stream Path:\x17163\x16689\x18229\x16382\x15196\x15255\x15133\x15375
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Stream Size:11247
      Base64 Encoded:True
      Data ASCII:< ? x m l v e r s i o n = " 1 . 0 " ? > . . < c o n f i g u r a t i o n > . . . < s t a r t u p > < s u p p o r t e d R u n t i m e v e r s i o n = " v . N E T F r a m e w o r k 4 C l i e n t P r o f i l e " / > < / s t a r t u p > . . . < r u n t i m e > . . . . < a s s e m b l y B i n d i n g x m l n s = " u r n : s c h e m a s - m i c r o s o f t - c o m : a s m . v 1 " a p p l i e s T o = " v 1 . 0 . 3 7 0 5 " > . . . . . < d e p e n d e n t A s s e m b l y > . . . . . . < a s s e m b l
      Data Raw:3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 3f 3e 0d 0a 3c 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 3e 0d 0a 09 3c 73 74 61 72 74 75 70 3e 3c 73 75 70 70 6f 72 74 65 64 52 75 6e 74 69 6d 65 20 76 65 72 73 69 6f 6e 3d 22 76 2e 4e 45 54 20 46 72 61 6d 65 77 6f 72 6b 20 34 20 43 6c 69 65 6e 74 20 50 72 6f 66 69 6c 65 22 2f 3e 3c 2f 73 74 61 72 74 75 70 3e 0d 0a 09 3c 72 75
      Stream Path: \x18496\x15167\x17394\x17464\x17841, File Type: data, Stream Size: 3328
      Stream Path:\x18496\x15167\x17394\x17464\x17841
      File Type:data
      Stream Size:3328
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . % . % . % . ' . ' . ' . + . + . + . , . , . , . - . - . - . . . . . . . . . . . . . . . 7 . 7 . 8 . 8 . = . = . = . = . = . = . = . = . = . B . B . B . B . P . P . P . P . P . P . P . P . T . T . X . X . Z . Z . Z . Z . Z . Z . Z . Z . _ . ` . ` . d . d . d . d . d . d . d . d . d . d . d . d . d . m . m . m . m . m . m . z . z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:06 00 06 00 06 00 06 00 06 00 06 00 06 00 06 00 06 00 06 00 1f 00 1f 00 1f 00 25 00 25 00 25 00 27 00 27 00 27 00 2b 00 2b 00 2b 00 2c 00 2c 00 2c 00 2d 00 2d 00 2d 00 2e 00 2e 00 2e 00 2e 00 2e 00 2e 00 2e 00 37 00 37 00 38 00 38 00 3d 00 3d 00 3d 00 3d 00 3d 00 3d 00 3d 00 3d 00 3d 00 42 00 42 00 42 00 42 00 50 00 50 00 50 00 50 00 50 00 50 00 50 00 50 00 54 00 54 00 58 00 58 00
      Stream Path: \x18496\x15518\x16925\x17915, File Type: data, Stream Size: 204
      Stream Path:\x18496\x15518\x16925\x17915
      File Type:data
      Stream Size:204
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . " . $ . % . & . ( . * . , . . . 0 . 2 . 4 . 6 . 8 . : . < . > . @ . B . D . F . H . J . L . N . P . R . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . " . # . % . & . ' . ) . + . - . / . 1 . 3 . 5 . 7 . 9 . ; . = . ? . A . C . E . G . I . K . M . O . Q .
      Data Raw:f3 03 f5 03 f7 03 f9 03 fb 03 fd 03 ff 03 01 04 03 04 05 04 07 04 09 04 0b 04 0d 04 0f 04 11 04 13 04 15 04 17 04 19 04 1b 04 1d 04 1e 04 20 04 21 04 22 04 24 04 25 04 26 04 28 04 2a 04 2c 04 2e 04 30 04 32 04 34 04 36 04 38 04 3a 04 3c 04 3e 04 40 04 42 04 44 04 46 04 48 04 4a 04 4c 04 4e 04 50 04 52 04 f2 03 f4 03 f6 03 f8 03 fa 03 fc 03 fe 03 00 04 02 04 04 04 06 04 08 04 0a 04
      Stream Path: \x18496\x16191\x17783\x17516\x15210\x17892\x18468, File Type: ASCII text, with very long lines, with CRLF line terminators, Stream Size: 42691
      Stream Path:\x18496\x16191\x17783\x17516\x15210\x17892\x18468
      File Type:ASCII text, with very long lines, with CRLF line terminators
      Stream Size:42691
      Base64 Encoded:True
      Data ASCII:N a m e T a b l e T y p e C o l u m n _ V a l i d a t i o n I d e n t i f i e r N S t r i n g c a t e g o r y T e x t ; F o r m a t t e d ; T e m p l a t e ; C o n d i t i o n ; G u i d ; P a t h ; V e r s i o n ; L a n g u a g e ; I d e n t i f i e r ; B i n a r y ; U p p e r C a s e ; L o w e r C a s e ; F i l e n a m e ; P a t h s ; A n y P a t h ; W i l d C a r d F i l e n a m e ; R e g P a t h ; K e y F o r m a t t e d ; C u s t o m S o u r c e ; P r o p e r t y ; C a b i n e t ; S h o r t c u t ; U
      Data Raw:4e 61 6d 65 54 61 62 6c 65 54 79 70 65 43 6f 6c 75 6d 6e 5f 56 61 6c 69 64 61 74 69 6f 6e 49 64 65 6e 74 69 66 69 65 72 4e 53 74 72 69 6e 67 20 63 61 74 65 67 6f 72 79 54 65 78 74 3b 46 6f 72 6d 61 74 74 65 64 3b 54 65 6d 70 6c 61 74 65 3b 43 6f 6e 64 69 74 69 6f 6e 3b 47 75 69 64 3b 50 61 74 68 3b 56 65 72 73 69 6f 6e 3b 4c 61 6e 67 75 61 67 65 3b 49 64 65 6e 74 69 66 69 65 72 3b
      Stream Path: \x18496\x16191\x17783\x17516\x15978\x17586\x18479, File Type: data, Stream Size: 4648
      Stream Path:\x18496\x16191\x17783\x17516\x15978\x17586\x18479
      File Type:data
      Stream Size:4648
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . . . 6 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . T . . . . . . . j . . . . . . . B . . . . . + . . . . . . . . . o . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ) . . . . . . . . . . . . . . . . . ( . . . . . . . 5 . . . . . . . . . . . . . . . O . . .
      Data Raw:e4 04 00 00 04 00 14 00 05 00 06 00 00 00 00 00 04 00 0c 00 06 00 02 00 0b 00 15 00 0a 00 99 00 01 00 07 01 0f 00 01 00 ca 00 01 00 01 00 ae 00 0b 00 1a 00 03 00 02 00 08 00 02 00 09 00 02 00 08 00 02 00 08 00 02 00 08 00 02 00 08 00 02 00 0e 00 01 00 04 00 81 00 15 00 01 00 24 00 01 00 36 00 01 00 15 00 01 00 15 00 01 00 05 00 01 00 1e 00 01 00 20 00 01 00 0d 00 01 00 0a 00 07 00
      Stream Path: \x18496\x16255\x16740\x16943\x18486, File Type: data, Stream Size: 176
      Stream Path:\x18496\x16255\x16740\x16943\x18486
      File Type:data
      Stream Size:176
      Base64 Encoded:False
      Data ASCII:. . . . % . ' . + . , . - . . . 7 . 8 . = . B . P . T . X . Z . _ . ` . d . m . z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . . 5 . 6 . 7 . < . ? . B . F . Q . b . d . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . : . J . [ . e . m . p . } . . .
      Data Raw:06 00 1f 00 25 00 27 00 2b 00 2c 00 2d 00 2e 00 37 00 38 00 3d 00 42 00 50 00 54 00 58 00 5a 00 5f 00 60 00 64 00 6d 00 7a 00 7f 00 81 00 87 00 8c 00 94 00 9d 00 a2 00 a7 00 ae 00 b5 00 b8 00 d5 00 dd 00 e6 00 eb 00 ef 00 f4 00 f7 00 07 01 16 01 19 01 1b 01 21 01 2e 01 35 01 36 01 37 01 3c 01 3f 01 42 01 46 01 51 01 62 01 64 01 80 01 8b 01 91 01 94 01 99 01 a1 01 a8 01 ad 01 b0 01
      Stream Path: \x18496\x16383\x16886\x16661\x17528\x17126\x17548\x16881\x17900\x17580\x18481, File Type: data, Stream Size: 6
      Stream Path:\x18496\x16383\x16886\x16661\x17528\x17126\x17548\x16881\x17900\x17580\x18481
      File Type:data
      Stream Size:6
      Base64 Encoded:False
      Data ASCII:. . . . . .
      Data Raw:a8 02 a7 02 a6 02
      Stream Path: \x18496\x16383\x17380\x16876\x17892\x17580\x18481, File Type: data, Stream Size: 10248
      Stream Path:\x18496\x16383\x17380\x16876\x17892\x17580\x18481
      File Type:data
      Stream Size:10248
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . % . % . % . ' . ' . ' . + . + . + . , . , . , . - . - . - . . . . . . . . . . . . . . . 7 . 7 . 8 . 8 . = . = . = . = . = . = . = . = . = . B . B . B . B . P . P . P . P . P . P . P . P . T . T . X . X . Z . Z . Z . Z . Z . Z . Z . Z . _ . ` . ` . d . d . d . d . d . d . d . d . d . d . d . d . d . m . m . m . m . m . m . z . z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:06 00 06 00 06 00 06 00 06 00 06 00 06 00 06 00 06 00 06 00 1f 00 1f 00 1f 00 25 00 25 00 25 00 27 00 27 00 27 00 2b 00 2b 00 2b 00 2c 00 2c 00 2c 00 2d 00 2d 00 2d 00 2e 00 2e 00 2e 00 2e 00 2e 00 2e 00 2e 00 37 00 37 00 38 00 38 00 3d 00 3d 00 3d 00 3d 00 3d 00 3d 00 3d 00 3d 00 3d 00 42 00 42 00 42 00 42 00 50 00 50 00 50 00 50 00 50 00 50 00 50 00 50 00 54 00 54 00 58 00 58 00
      Stream Path: \x18496\x16667\x17191\x15090\x17912\x17591\x18481, File Type: data, Stream Size: 72
      Stream Path:\x18496\x16667\x17191\x15090\x17912\x17591\x18481
      File Type:data
      Stream Size:72
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . u . . . u . . . . . . . . . . . . . . . . . \\ . \\ . \\ . \\ . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:bf 03 bf 03 80 04 80 04 01 80 02 80 01 80 02 80 be 03 75 02 be 03 75 02 00 80 00 80 00 80 00 80 00 80 12 80 00 80 12 80 5c 81 5c 81 5c 81 5c 81 11 80 11 80 11 80 11 80 de 03 df 03 de 03 df 03 00 00 00 00 00 00 00 00
      Stream Path: \x18496\x16842\x17200\x15281\x16955\x17958\x16951\x16924\x17972\x17512\x16934, File Type: data, Stream Size: 54
      Stream Path:\x18496\x16842\x17200\x15281\x16955\x17958\x16951\x16924\x17972\x17512\x16934
      File Type:data
      Stream Size:54
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . < .
      Data Raw:a1 02 de 02 df 02 e2 02 e4 02 e5 02 01 03 1a 03 1b 03 a2 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ee 82 20 83 84 83 e8 83 78 85 dc 85 a0 8f c8 99 3c 8f
      Stream Path: \x18496\x16842\x17200\x16305\x16146\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 72
      Stream Path:\x18496\x16842\x17200\x16305\x16146\x17704\x16952\x16817\x18472
      File Type:data
      Stream Size:72
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . 2 . 3 . 4 . 5 . T . V . . . . . . . . . . . . . . . . . . . 0 . . . Z . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:a1 02 de 02 df 02 e2 02 1c 03 32 03 33 03 34 03 35 03 54 04 56 04 81 04 a2 02 00 00 00 00 00 00 00 00 00 00 00 00 2e 03 30 03 00 00 5a 04 00 00 ee 82 20 83 84 83 e8 83 14 85 fe 7f fd 7f e7 83 e6 83 13 85 e9 83 ff 7f
      Stream Path: \x18496\x16842\x17913\x18126\x16808\x17912\x16168\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 96
      Stream Path:\x18496\x16842\x17913\x18126\x16808\x17912\x16168\x17704\x16952\x16817\x18472
      File Type:data
      Stream Size:96
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . j . r . . . . . \\ . . . $ . 8 . . . . . . .
      Data Raw:a1 02 de 02 e2 02 e4 02 e5 02 e8 02 e9 02 04 03 05 03 06 03 07 03 08 03 15 03 16 03 17 03 1a 03 a2 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ee 82 20 83 e8 83 78 85 dc 85 6a 98 72 86 94 91 f8 91 5c 92 c0 92 24 93 38 98 9c 98 00 99 c8 99
      Stream Path: \x18496\x16911\x17892\x17784\x15144\x17458\x17587\x16945\x17905\x18486, File Type: data, Stream Size: 32
      Stream Path:\x18496\x16911\x17892\x17784\x15144\x17458\x17587\x16945\x17905\x18486
      File Type:data
      Stream Size:32
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:84 02 84 02 84 02 84 02 84 02 84 02 84 02 84 02 87 02 8d 02 91 02 95 02 99 02 cc 02 d1 02 d6 02
      Stream Path: \x18496\x16911\x17892\x17784\x18472, File Type: data, Stream Size: 16
      Stream Path:\x18496\x16911\x17892\x17784\x18472
      File Type:data
      Stream Size:16
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . .
      Data Raw:84 02 00 00 00 00 00 00 02 80 01 80 83 02 00 80
      Stream Path: \x18496\x16918\x17191\x18468, File Type: MIPSEB Ucode, Stream Size: 12
      Stream Path:\x18496\x16918\x17191\x18468
      File Type:MIPSEB Ucode
      Stream Size:12
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . .
      Data Raw:01 80 05 80 00 00 89 04 00 00 00 00
      Stream Path: \x18496\x16923\x17194\x17910\x18229, File Type: data, Stream Size: 36
      Stream Path:\x18496\x16923\x17194\x17910\x18229
      File Type:data
      Stream Size:36
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:cf 02 d4 02 d8 02 01 80 01 80 01 80 ce 02 d3 02 d3 02 00 00 00 00 d7 02 cd 02 d2 02 00 00 cc 02 d1 02 d6 02
      Stream Path: \x18496\x16925\x17915\x17884\x17404\x18472, File Type: data, Stream Size: 36
      Stream Path:\x18496\x16925\x17915\x17884\x17404\x18472
      File Type:data
      Stream Size:36
      Base64 Encoded:False
      Data ASCII:^ . _ . . . ] . ] . ] . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:5e 03 5f 03 f0 03 5d 03 5d 03 5d 03 09 80 0c 80 09 80 00 00 00 80 00 00 00 80 00 00 00 80 00 80 01 80 00 80
      Stream Path: \x18496\x17163\x16689\x18229, File Type: data, Stream Size: 20
      Stream Path:\x18496\x17163\x16689\x18229
      File Type:data
      Stream Size:20
      Base64 Encoded:False
      Data ASCII:. . . . G . b . d . . . . . . . . . . .
      Data Raw:a9 02 b2 02 47 03 62 03 64 03 01 00 01 00 01 00 01 00 01 00
      Stream Path: \x18496\x17165\x16949\x17894\x17778\x18492, File Type: data, Stream Size: 18
      Stream Path:\x18496\x17165\x16949\x17894\x17778\x18492
      File Type:data
      Stream Size:18
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . .
      Data Raw:83 02 9c 02 9e 02 00 00 83 02 83 02 9f 02 9b 02 9d 02
      Stream Path: \x18496\x17165\x17380\x17074, File Type: data, Stream Size: 484
      Stream Path:\x18496\x17165\x17380\x17074
      File Type:data
      Stream Size:484
      Base64 Encoded:False
      Data ASCII:+ . - . / . 1 . 2 . 3 . 4 . 5 . < . W . a . l . q . { . . . . . . . T . V . a . u . . . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . u . u . u . u . u . u . u . u . u . . . J . . . i . i . 9 . u . u . u . u . u . u . u . . . . . . . . . . . . . . . . . . . N . e . N . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:2b 03 2d 03 2f 03 31 03 32 03 33 03 34 03 35 03 3c 03 57 03 61 03 6c 03 71 03 7b 03 86 03 c2 03 e1 03 54 04 56 04 61 04 75 04 81 04 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80
      Stream Path: \x18496\x17167\x16943, File Type: GPG encrypted data, Stream Size: 90
      Stream Path:\x18496\x17167\x16943
      File Type:GPG encrypted data
      Stream Size:90
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . [ . . ; . . . . . . . . . . . . [ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:85 02 8b 02 8f 02 93 02 97 02 87 02 8d 02 91 02 95 02 99 02 8a 02 8e 02 92 02 96 02 9a 02 f0 5b 0e 80 3b 01 00 80 f0 f9 0d 80 f0 f9 0d 80 f0 5b 0e 80 89 02 00 00 89 02 89 02 89 02 88 02 00 00 88 02 88 02 88 02 00 82 00 82 00 82 00 82 00 82 01 80 02 80 03 80 04 80 05 80
      Stream Path: \x18496\x17490\x17910\x17380\x15279\x16955\x17958\x16951\x16924\x17972\x17512\x16934, File Type: data, Stream Size: 420
      Stream Path:\x18496\x17490\x17910\x17380\x15279\x16955\x17958\x16951\x16924\x17972\x17512\x16934
      File Type:data
      Stream Size:420
      Base64 Encoded:False
      Data ASCII:7 . X . _ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:37 00 58 00 5f 00 a1 02 ab 02 b4 02 c7 02 da 02 db 02 dc 02 dd 02 de 02 df 02 e1 02 e2 02 e3 02 e4 02 e5 02 e6 02 e7 02 e8 02 e9 02 ea 02 eb 02 ed 02 ee 02 ef 02 f0 02 f1 02 f2 02 f3 02 f4 02 f5 02 f6 02 f7 02 f8 02 f9 02 fa 02 fb 02 fc 02 fd 02 fe 02 ff 02 00 03 01 03 02 03 03 03 04 03 05 03 06 03 07 03 08 03 09 03 0a 03 0b 03 0c 03 0d 03 0e 03 0f 03 10 03 11 03 12 03 13 03 14 03
      Stream Path: \x18496\x17490\x17910\x17380\x16303\x16146\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 132
      Stream Path:\x18496\x17490\x17910\x17380\x16303\x16146\x17704\x16952\x16817\x18472
      File Type:data
      Stream Size:132
      Base64 Encoded:False
      Data ASCII:7 . _ . . . . . . . . . . . . . . . . . . . . . . . . . . . + . - . / . 1 . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . , . . . 0 . . . . . Z . d . . . . . . . . . . . . . . . X . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:37 00 5f 00 a1 02 ab 02 b4 02 ca 02 da 02 db 02 dc 02 dd 02 de 02 df 02 e1 02 e2 02 1c 03 2b 03 2d 03 2f 03 31 03 3c 03 c2 03 e1 03 00 00 b5 02 a2 02 00 00 b5 02 cb 02 00 00 b5 02 b5 02 00 00 00 00 00 00 e0 02 00 00 00 00 00 00 2c 03 2e 03 30 03 00 00 00 00 5a 04 64 80 f4 81 ee 82 01 80 8f 81 05 80 c8 80 90 81 58 82 bc 82 20 83 84 83 b6 83 e8 83 14 85 fe 7f fd 7f e7 83 e6 83 13 85
      Stream Path: \x18496\x17548\x17648\x17522\x17512\x18487, File Type: data, Stream Size: 96
      Stream Path:\x18496\x17548\x17648\x17522\x17512\x18487
      File Type:data
      Stream Size:96
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:87 02 8d 02 91 02 95 02 99 02 cc 02 d1 02 d6 02 86 02 8c 02 90 02 94 02 98 02 d0 02 d5 02 d9 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 00 81 00 81 00 81 00 81 00 81 04 81 04 81 04 81 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 85 02 8b 02 8f 02 93 02 97 02 cf 02 d4 02 d8 02
      Stream Path: \x18496\x17548\x17905\x17589\x15151\x17522\x17191\x17207\x17522, File Type: data, Stream Size: 480
      Stream Path:\x18496\x17548\x17905\x17589\x15151\x17522\x17191\x17207\x17522
      File Type:data
      Stream Size:480
      Base64 Encoded:False
      Data ASCII:+ . + . + . + . - . - . - . - . 2 . 2 . 2 . 2 . 3 . 3 . 3 . 3 . < . < . < . < . < . < . < . < . q . q . q . q . { . { . { . { . . . . . . . . . . . . . . . . . T . T . T . T . T . T . T . T . V . V . V . V . a . a . u . u . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . L . L . N . N . P . P . R . R . u . u . w . w . . . . . . . . . k . k . . . . . . . . . 8 . 8 . L . L . N . N . P . P . R . R . 8 . 8 . . . . . 8 . 8 . 8 . 8 . k . k . . . . . T . V . T . V . T . V . T . V .
      Data Raw:2b 03 2b 03 2b 03 2b 03 2d 03 2d 03 2d 03 2d 03 32 03 32 03 32 03 32 03 33 03 33 03 33 03 33 03 3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 71 03 71 03 71 03 71 03 7b 03 7b 03 7b 03 7b 03 c2 03 c2 03 c2 03 c2 03 c2 03 c2 03 e1 03 e1 03 54 04 54 04 54 04 54 04 54 04 54 04 54 04 54 04 56 04 56 04 56 04 56 04 61 04 61 04 75 04 75 04 81 04 81 04 81 04 81 04 c6 03 c6 03 cd 03 cd 03
      Stream Path: \x18496\x17548\x17905\x17589\x15279\x16953\x17905, File Type: data, Stream Size: 840
      Stream Path:\x18496\x17548\x17905\x17589\x15279\x16953\x17905
      File Type:data
      Stream Size:840
      Base64 Encoded:False
      Data ASCII:+ . - . / . / . / . / . / . / . 1 . 1 . 2 . 3 . 4 . 4 . 4 . 4 . 4 . 4 . 5 . 5 . < . W . W . a . a . a . a . a . a . a . l . l . l . l . q . { . { . { . . . . . . . . . . . . . . . . . . . . . . . T . V . V . V . V . a . a . a . a . a . a . a . a . a . a . a . u . u . u . u . . . . . . . ; . . . . . . . . . . . ; . . . . . . . ; . . . . . . . . . . . ; . . . ; . f . h . . . . . . . . . . . . . . . f . f . h . h . p . z . | . ~ . ; . ; . p . p . . . . . . . 8 . ; . > . > . ; . 8 . ; . > . > . 8 . ; . > . > .
      Data Raw:2b 03 2d 03 2f 03 2f 03 2f 03 2f 03 2f 03 2f 03 31 03 31 03 32 03 33 03 34 03 34 03 34 03 34 03 34 03 34 03 35 03 35 03 3c 03 57 03 57 03 61 03 61 03 61 03 61 03 61 03 61 03 61 03 6c 03 6c 03 6c 03 6c 03 71 03 7b 03 7b 03 7b 03 86 03 86 03 86 03 86 03 86 03 86 03 c2 03 e1 03 e1 03 e1 03 e1 03 54 04 56 04 56 04 56 04 56 04 61 04 61 04 61 04 61 04 61 04 61 04 61 04 61 04 61 04 61 04
      Stream Path: \x18496\x17548\x17905\x17589\x18479, File Type: data, Stream Size: 4784
      Stream Path:\x18496\x17548\x17905\x17589\x18479
      File Type:data
      Stream Size:4784
      Base64 Encoded:False
      Data ASCII:+ . + . + . + . + . + . + . + . + . - . - . - . - . - . - . - . - . - . / . / . / . / . / . / . / . / . / . 1 . 1 . 1 . 1 . 1 . 1 . 1 . 1 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 3 . 3 . 3 . 3 . 3 . 3 . 3 . 3 . 3 . 4 . 4 . 4 . 4 . 4 . 4 . 4 . 4 . 4 . 5 . 5 . 5 . 5 . 5 . 5 . 5 . 5 . < . < . < . < . < . < . < . < . < . < . < . < . W . W . W . a . a . a . a . a . a . a . a . l . l . l . q . q . q . q . { . { . { . { . { . { . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:2b 03 2b 03 2b 03 2b 03 2b 03 2b 03 2b 03 2b 03 2b 03 2d 03 2d 03 2d 03 2d 03 2d 03 2d 03 2d 03 2d 03 2d 03 2f 03 2f 03 2f 03 2f 03 2f 03 2f 03 2f 03 2f 03 2f 03 31 03 31 03 31 03 31 03 31 03 31 03 31 03 31 03 32 03 32 03 32 03 32 03 32 03 32 03 32 03 32 03 32 03 33 03 33 03 33 03 33 03 33 03 33 03 33 03 33 03 33 03 34 03 34 03 34 03 34 03 34 03 34 03 34 03 34 03 34 03 35 03 35 03
      Stream Path: \x18496\x17558\x17959\x16943\x17180\x17514\x17892\x17784\x18472, File Type: data, Stream Size: 66
      Stream Path:\x18496\x17558\x17959\x16943\x17180\x17514\x17892\x17784\x18472
      File Type:data
      Stream Size:66
      Base64 Encoded:False
      Data ASCII:. . 6 . ` . . . . . . . S . U . ` . t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:1e 03 36 03 60 03 bd 03 e0 03 ef 03 53 04 55 04 60 04 74 04 7f 04 09 84 09 84 09 84 09 84 09 84 09 84 09 84 09 84 09 84 09 84 09 84 1d 03 1d 03 1d 03 1d 03 1d 03 1d 03 1d 03 1d 03 1d 03 1d 03 1d 03
      Stream Path: \x18496\x17630\x17770\x16868\x18472, File Type: data, Stream Size: 32
      Stream Path:\x18496\x17630\x17770\x16868\x18472
      File Type:data
      Stream Size:32
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:ba 02 ba 02 00 00 bb 02 bb 02 00 00 00 00 00 00 00 00 00 80 02 01 00 80 00 00 00 00 c2 02 c4 02
      Stream Path: \x18496\x17753\x17650\x17768\x18231, File Type: data, Stream Size: 108
      Stream Path:\x18496\x17753\x17650\x17768\x18231
      File Type:data
      Stream Size:108
      Base64 Encoded:False
      Data ASCII:w . . . . . . . . . . . . . . . . . . . . . . " . $ . & . ( . * . a . c . e . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . # . % . ' . ) . a . b . d . . . . . . . a . V . u . a .
      Data Raw:77 02 ad 02 af 02 b1 02 b7 02 b9 02 bc 02 be 02 bf 02 c1 02 c3 02 20 03 22 03 24 03 26 03 28 03 2a 03 61 03 63 03 65 03 bf 03 f1 03 80 04 85 04 86 04 87 04 88 04 ba 02 ac 02 ae 02 b0 02 b6 02 b8 02 bb 02 bd 02 bd 02 c0 02 c5 02 1f 03 21 03 23 03 25 03 27 03 29 03 61 03 62 03 64 03 be 03 f0 03 be 03 61 04 56 04 75 04 61 04
      Stream Path: \x18496\x17932\x17910\x17458\x16778\x17207\x17522, File Type: data, Stream Size: 40
      Stream Path:\x18496\x17932\x17910\x17458\x16778\x17207\x17522
      File Type:data
      Stream Size:40
      Base64 Encoded:False
      Data ASCII:. . . . . . . . . . 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Data Raw:a1 02 ab 02 b4 02 c7 02 ca 02 33 81 01 80 01 80 13 80 13 80 83 02 a9 02 a9 02 00 00 00 00 a0 02 aa 02 b3 02 c6 02 c9 02
      Stream Path: \x18496\x17998\x17512\x15799\x17636\x17203\x17073, File Type: data, Stream Size: 192
      Stream Path:\x18496\x17998\x17512\x15799\x17636\x17203\x17073
      File Type:data
      Stream Size:192
      Base64 Encoded:False
      Data ASCII:< . < . < . < . < . < . < . < . < . < . < . < . T . T . T . T . T . T . T . T . T . T . T . T . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . C . . . . . . . . . . . . . . . . . . . . . [ . \\ . . . . . . . . . . . . . . . . . . . . . [ . \\ . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z . Z .
      Data Raw:3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 3c 03 54 04 54 04 54 04 54 04 54 04 54 04 54 04 54 04 54 04 54 04 54 04 54 04 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 43 03 ed 02 ee 02 f4 02 fd 02 00 03 01 03 09 03 0a 03 12 03 1b 03 5b 03 5c 03 ed 02 ee 02 f4 02 fd 02

      Network Behavior

      No network behavior found

      Code Manipulations


      CPU Usage

      Click to jump to process

      Memory Usage

      Click to jump to process


      Click to jump to process

      System Behavior


      Start time:12:22:31
      Start date:29/11/2020
      Wow64 process (32bit):false
      Commandline:'C:\Windows\System32\msiexec.exe' /i 'C:\Users\user\Desktop\CID_x64.msi'
      File size:66048 bytes
      MD5 hash:4767B71A318E201188A0D0A420C8B608
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language


      Start time:12:22:33
      Start date:29/11/2020
      Wow64 process (32bit):true
      Commandline:C:\Windows\syswow64\MsiExec.exe -Embedding 7C2160B8C719111621BBF907BA5D9B1C C
      File size:59904 bytes
      MD5 hash:12C17B5A5C2A7B97342C362CA467E9A2
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language


      Start time:12:22:36
      Start date:29/11/2020
      Wow64 process (32bit):true
      Commandline:C:\Windows\syswow64\MsiExec.exe -Embedding 67B6CF52D8EDBBB744EA0BA0249B0181
      File size:59904 bytes
      MD5 hash:12C17B5A5C2A7B97342C362CA467E9A2
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language


      Code Analysis

      Reset < >