What is launcher.exe?

launcher.exe is part of Opera Internet Browser and developed by Opera Software according to the launcher.exe version information.

launcher.exe's description is "Opera Internet Browser"

launcher.exe is digitally signed by Opera Software AS.

launcher.exe is usually located in the 'c:\users\%USERNAME%\appdata\local\programs\opera\' folder.

None of the anti-virus scanners at VirusTotal reports anything malicious about launcher.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

The following is the available information on launcher.exe:

PropertyValue
Product nameOpera Internet Browser
Company nameOpera Software
File descriptionOpera Internet Browser
Internal nameOpera
Legal copyrightCopyright Opera Software 2019
Product version64.0.3417.92
File version64.0.3417.92

Here's a screenshot of the file properties when displayed by Windows Explorer:

Product nameOpera Internet Browser
Company nameOpera Software
File descriptionOpera Internet Browser
Internal nameOpera
Legal copyrightCopyright Opera Software 2019
Product version64.0.3417.92
File version64.0.3417.92

Digital signatures [?]

launcher.exe has a valid digital signature.

PropertyValue
Signer nameOpera Software AS
Certificate issuer nameDigiCert EV Code Signing CA (SHA2)
Certificate serial number05f4210db2b283a32ff2aed29fcb68a4

VirusTotal report

None of the 71 anti-virus programs at VirusTotal detected the launcher.exe file.

None of the 71 anti-virus programs detected the launcher.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "dll_loaded": [
        "kernel32"
    ],
    "file_failed": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\installation_status.json"
    ],
    "regkey_opened": [
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MPlayer2",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\AddressBook",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SchedulingAgent",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Fontcore",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Connection Manager",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE5BAKEX",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE40",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MozillaMaintenanceService",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IEData",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DirectDrawEx",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox 60.0.2 (x86 sv-SE)",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WIC",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{0398A685-FD8D-46B3-9816-C47319B0CF5f}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE4Data",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MobileOptionPack",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DXM_Runtime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion"
    ],
    "file_exists": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\opera.exe",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\64.0.3417.92\\opera.exe",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\installation_status.xml",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\installation_status.json"
    ],
    "regkey_read": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UBR",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ReleaseId"
    ],
    "directory_enumerated": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\old_status\\*",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\*"
    ]
}

Generic

[
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\f6a9fabb4178a9108f34150ff44c796f6438e7f32bf64cf421b5b34f5be4c799.bin",
        "process_name": "f6a9fabb4178a9108f34150ff44c796f6438e7f32bf64cf421b5b34f5be4c799.bin",
        "pid": 2456,
        "summary": {
            "dll_loaded": [
                "kernel32"
            ],
            "file_failed": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\installation_status.json"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MPlayer2",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\AddressBook",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SchedulingAgent",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Fontcore",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Connection Manager",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE5BAKEX",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE40",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MozillaMaintenanceService",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IEData",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DirectDrawEx",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox 60.0.2 (x86 sv-SE)",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WIC",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{0398A685-FD8D-46B3-9816-C47319B0CF5f}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE4Data",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MobileOptionPack",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DXM_Runtime",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion"
            ],
            "file_exists": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\opera.exe",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\64.0.3417.92\\opera.exe",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\installation_status.xml",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\installation_status.json"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UBR",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ReleaseId"
            ],
            "directory_enumerated": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\old_status\\*",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\*"
            ]
        },
        "first_seen": 1573444385.5156,
        "ppid": 2780
    },
    {
        "process_path": "C:\\Windows\\System32\\lsass.exe",
        "process_name": "lsass.exe",
        "pid": 476,
        "summary": {},
        "first_seen": 1573444385.3281,
        "ppid": 376
    }
]

Signatures

[
    {
        "markcount": 1,
        "families": [],
        "description": "This executable has a PDB path",
        "severity": 1,
        "marks": [
            {
                "category": "pdb_path",
                "ioc": "launcher.exe.pdb",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "has_pdb"
    },
    {
        "markcount": 4,
        "families": [],
        "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
        "severity": 1,
        "marks": [
            {
                "category": "section",
                "ioc": ".00cfg",
                "type": "ioc",
                "description": null
            },
            {
                "category": "section",
                "ioc": ".retplne",
                "type": "ioc",
                "description": null
            },
            {
                "category": "section",
                "ioc": "CPADinfo",
                "type": "ioc",
                "description": null
            },
            {
                "category": "section",
                "ioc": "prot",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_features"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "The file contains an unknown PE resource name possibly indicative of a packer",
        "severity": 1,
        "marks": [
            {
                "category": "resource name",
                "ioc": "PNG",
                "type": "ioc",
                "description": null
            },
            {
                "category": "resource name",
                "ioc": "TXT",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_unknown_resource_name"
    },
    {
        "markcount": 45,
        "families": [],
        "description": "Foreign language identified in PE resource",
        "severity": 2,
        "marks": [
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            },
            {
                "name": "RT_STRING",
                "language": "LANG_SERBIAN",
                "offset": "0x00181c60",
                "filetype": "data",
                "sublanguage": "SUBLANG_SERBIAN_CYRILLIC",
                "type": "generic",
                "size": "0x000001be"
            }
        ],
        "references": [],
        "name": "origin_langid"
    },
    {
        "markcount": 33,
        "families": [],
        "description": "Queries for potentially installed applications",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "registry",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "RegOpenKeyExW",
                    "return_value": 2,
                    "arguments": {
                        "access": "0x00020019",
                        "base_handle": "0xffffffff80000001",
                        "key_handle": "0x0000000000000000",
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "options": 0
                    },
                    "time": 1573444385.6716,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 106
            },
            {
                "call": {
                    "category": "registry",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "RegOpenKeyExW",
                    "return_value": 2,
                    "arguments": {
                        "access": "0x00020019",
                        "base_handle": "0xffffffff80000001",
                        "key_handle": "0x0000000000000000",
                        "regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "options": 0
                    },
                    "time": 1573444385.6716,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 107
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000ec",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "options": 0
                    },
                    "time": 1573444385.6716,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 117
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f0",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "options": 0
                    },
                    "time": 1573444385.6716,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 118
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\AddressBook",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\AddressBook",
                        "options": 0
                    },
                    "time": 1573444385.6716,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 120
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Connection Manager",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Connection Manager",
                        "options": 0
                    },
                    "time": 1573444385.6716,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 122
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DirectDrawEx",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DirectDrawEx",
                        "options": 0
                    },
                    "time": 1573444385.6716,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 125
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DXM_Runtime",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DXM_Runtime",
                        "options": 0
                    },
                    "time": 1573444385.6716,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 128
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Fontcore",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Fontcore",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 131
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE40",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE40",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 134
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE4Data",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE4Data",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 137
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE5BAKEX",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE5BAKEX",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 140
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IEData",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IEData",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 143
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MobileOptionPack",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MobileOptionPack",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 146
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MozillaMaintenanceService",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MozillaMaintenanceService",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 149
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MPlayer2",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MPlayer2",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 152
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SchedulingAgent",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SchedulingAgent",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 155
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WIC",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WIC",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 158
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020119",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{0398A685-FD8D-46B3-9816-C47319B0CF5f}",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{0398A685-FD8D-46B3-9816-C47319B0CF5f}",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 161
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000ec",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 167
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f0",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 168
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\AddressBook",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\AddressBook",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 170
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Connection Manager",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Connection Manager",
                        "options": 0
                    },
                    "time": 1573444385.6876,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 172
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DirectDrawEx",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DirectDrawEx",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 175
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Fontcore",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Fontcore",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 178
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE40",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE40",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 181
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE4Data",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE4Data",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 184
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE5BAKEX",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IE5BAKEX",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 187
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IEData",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\IEData",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 190
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MobileOptionPack",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MobileOptionPack",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 193
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox 60.0.2 (x86 sv-SE)",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox 60.0.2 (x86 sv-SE)",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 196
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f4",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SchedulingAgent",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SchedulingAgent",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 199
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "RegOpenKeyExW",
                    "return_value": 0,
                    "arguments": {
                        "access": "0x00020219",
                        "base_handle": "0xffffffff80000002",
                        "key_handle": "0x00000000000000f8",
                        "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WIC",
                        "regkey_r": "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\WIC",
                        "options": 0
                    },
                    "time": 1573444385.7036,
                    "tid": 2676,
                    "flags": {}
                },
                "pid": 2456,
                "type": "call",
                "cid": 202
            }
        ],
        "references": [],
        "name": "queries_programs"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 546,
            "time": 3.0791850090027,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 3130,
            "time": 3.0236809253693,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 3458,
            "time": 1.0471029281616,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 3786,
            "time": 3.0375480651855,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 4114,
            "time": 1.6495909690857,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 4442,
            "time": -0.090639114379883,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 4770,
            "time": 1.6097049713135,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 9246,
            "time": 1.0783219337463,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 13438,
            "time": 3.1257541179657,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "4c8e42cee7eb3f0a2c931e4027e4991fc9d33a53212de058bde0fa558b4f9e54",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "c8a75cb2079353f008c8792e303ecce67c5bd3407d5efbfe5f8fae929f09b4e3",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandbox

Other files also named launcher.exe

launcher.exe (197 votes)

Hashes [?]

PropertyValue
MD55e4efc9426033272077e105cfb1d45fc
SHA256f6a9fabb4178a9108f34150ff44c796f6438e7f32bf64cf421b5b34f5be4c799

Error Messages

These are some of the error messages that can appear related to launcher.exe:

launcher.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

launcher.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

Opera Internet Browser has stopped working.

End Program - launcher.exe. This program is not responding.

launcher.exe is not a valid Win32 application.

launcher.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with launcher.exe?

To help other users, please let us know what you will do with launcher.exe:



Malware or legitimate?

If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.

Please select the option that best describe your thoughts on the information provided on this web page


Free online surveys

And now some shameless self promotion ;)

A screenshot of FreeFixer's scan result.Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/2008/2016/2019/Vista/7/8/8.1/10. Supports both 32- and 64-bit Windows.

If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.

Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply