Windows Analysis Report
RecMin_Free_Install_v_2023_r1.zip

Overview

General Information

Sample name: RecMin_Free_Install_v_2023_r1.zip
Analysis ID: 1546135
MD5: ad47ddb1e8b4d4b30ce4a2dae1bd377a
SHA1: 905f92636bfc645f9745ebc1f431cbd1efd3c93e
SHA256: 46d6594dc87a5a143c86d699f38122ce96a0b8591b6b923ea5c05d01963de63e
Infos:

Detection

Score: 25
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Drops executables to the windows directory (C:\Windows) and starts them
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
Queries the volume information (name, serial number etc) of a device
Sigma detected: Startup Folder File Write
Stores files to the Windows start menu directory

Classification

Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData\Roaming
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\ST6UNST.000
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\SETUP.LST
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\RMedit.CAB
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\temp.000
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\Setup1.exe
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\ST6UNST.000
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\SETUP.LST
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\RMedit.CAB
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\temp.000
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\WINDOWS\Setup1.exe
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File deleted: C:\Windows\SETUP.LST
Source: classification engine Classification label: sus25.evad.winZIP@13/10@0/0
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\ST6UNST Uninstaller.LNK
Source: C:\Windows\Setup1.exe Mutant created: NULL
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Users\user\AppData\Local\Temp\msftqws.pdw
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File read: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Windows\System32\rundll32.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe "C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe"
Source: unknown Process created: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe "C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe"
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process created: C:\Windows\Setup1.exe C:\WINDOWS\Setup1.exe "C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\" "C:\WINDOWS\ST6UNST.000" "C:\WINDOWS\st6unst.exe"
Source: C:\Windows\Setup1.exe Process created: C:\Windows\ST6UNST.EXE C:\WINDOWS\st6unst.exe -n "C:\Windows\ST6UNST.000" -e 3 -f -w 5952
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process created: C:\Windows\Setup1.exe C:\WINDOWS\Setup1.exe "C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\" "C:\WINDOWS\ST6UNST.000" "C:\WINDOWS\st6unst.exe"
Source: C:\Windows\Setup1.exe Process created: C:\Windows\ST6UNST.EXE C:\WINDOWS\st6unst.exe -n "C:\Windows\ST6UNST.000" -e 3 -f -w 5952
Source: unknown Process created: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe "C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe"
Source: unknown Process created: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe "C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe"
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process created: C:\Windows\Setup1.exe C:\WINDOWS\Setup1.exe "C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\" "C:\WINDOWS\ST6UNST.000" "C:\WINDOWS\st6unst.exe"
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process created: C:\Windows\Setup1.exe C:\WINDOWS\Setup1.exe "C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\" "C:\WINDOWS\ST6UNST.000" "C:\WINDOWS\st6unst.exe"
Source: C:\Windows\Setup1.exe Process created: C:\Windows\ST6UNST.EXE C:\WINDOWS\st6unst.exe -n "C:\Windows\ST6UNST.000" -e 3 -f -w 3044
Source: C:\Windows\Setup1.exe Process created: C:\Windows\ST6UNST.EXE C:\WINDOWS\st6unst.exe -n "C:\Windows\ST6UNST.000" -e 3 -f -w 3044
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: acgenral.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: winmm.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: samcli.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: msacm32.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: urlmon.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: mpr.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: sspicli.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: iertutil.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: srvcli.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: netutils.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: aclayers.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: sfc.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: sfc_os.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: cabinet.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: propsys.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: profapi.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: linkinfo.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: ntshrui.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: cscapi.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: vb6stkit.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: comcat.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: olepro32.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: msvbvm60.dll
Source: C:\Windows\Setup1.exe Section loaded: apphelp.dll
Source: C:\Windows\Setup1.exe Section loaded: acgenral.dll
Source: C:\Windows\Setup1.exe Section loaded: uxtheme.dll
Source: C:\Windows\Setup1.exe Section loaded: winmm.dll
Source: C:\Windows\Setup1.exe Section loaded: samcli.dll
Source: C:\Windows\Setup1.exe Section loaded: msacm32.dll
Source: C:\Windows\Setup1.exe Section loaded: version.dll
Source: C:\Windows\Setup1.exe Section loaded: userenv.dll
Source: C:\Windows\Setup1.exe Section loaded: dwmapi.dll
Source: C:\Windows\Setup1.exe Section loaded: urlmon.dll
Source: C:\Windows\Setup1.exe Section loaded: mpr.dll
Source: C:\Windows\Setup1.exe Section loaded: sspicli.dll
Source: C:\Windows\Setup1.exe Section loaded: winmmbase.dll
Source: C:\Windows\Setup1.exe Section loaded: winmmbase.dll
Source: C:\Windows\Setup1.exe Section loaded: iertutil.dll
Source: C:\Windows\Setup1.exe Section loaded: srvcli.dll
Source: C:\Windows\Setup1.exe Section loaded: netutils.dll
Source: C:\Windows\Setup1.exe Section loaded: aclayers.dll
Source: C:\Windows\Setup1.exe Section loaded: sfc.dll
Source: C:\Windows\Setup1.exe Section loaded: sfc_os.dll
Source: C:\Windows\Setup1.exe Section loaded: msvbvm60.dll
Source: C:\Windows\Setup1.exe Section loaded: windows.storage.dll
Source: C:\Windows\Setup1.exe Section loaded: wldp.dll
Source: C:\Windows\Setup1.exe Section loaded: profapi.dll
Source: C:\Windows\Setup1.exe Section loaded: vb6zz.dll
Source: C:\Windows\Setup1.exe Section loaded: vb6es.dll
Source: C:\Windows\Setup1.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\Setup1.exe Section loaded: sxs.dll
Source: C:\Windows\Setup1.exe Section loaded: propsys.dll
Source: C:\Windows\Setup1.exe Section loaded: textinputframework.dll
Source: C:\Windows\Setup1.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\Setup1.exe Section loaded: coremessaging.dll
Source: C:\Windows\Setup1.exe Section loaded: ntmarta.dll
Source: C:\Windows\Setup1.exe Section loaded: wintypes.dll
Source: C:\Windows\Setup1.exe Section loaded: wintypes.dll
Source: C:\Windows\Setup1.exe Section loaded: wintypes.dll
Source: C:\Windows\Setup1.exe Section loaded: textshaping.dll
Source: C:\Windows\Setup1.exe Section loaded: vb6stkit.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: apphelp.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: acgenral.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: uxtheme.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: winmm.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: samcli.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: msacm32.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: version.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: userenv.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: dwmapi.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: urlmon.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: mpr.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: sspicli.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: winmmbase.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: winmmbase.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: iertutil.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: srvcli.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: netutils.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: aclayers.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: sfc.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: sfc_os.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: kernel.appcore.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: textinputframework.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: coreuicomponents.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: coremessaging.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: ntmarta.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: coremessaging.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: wintypes.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: wintypes.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: wintypes.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: textshaping.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: windows.storage.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: wldp.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: propsys.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: profapi.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: acgenral.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: winmm.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: samcli.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: msacm32.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: urlmon.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: mpr.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: sspicli.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: iertutil.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: srvcli.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: netutils.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: aclayers.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: sfc.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: sfc_os.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: cabinet.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: propsys.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: profapi.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: linkinfo.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: ntshrui.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: cscapi.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: vb6stkit.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: comcat.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: olepro32.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Section loaded: msvbvm60.dll
Source: C:\Windows\Setup1.exe Section loaded: apphelp.dll
Source: C:\Windows\Setup1.exe Section loaded: acgenral.dll
Source: C:\Windows\Setup1.exe Section loaded: uxtheme.dll
Source: C:\Windows\Setup1.exe Section loaded: winmm.dll
Source: C:\Windows\Setup1.exe Section loaded: samcli.dll
Source: C:\Windows\Setup1.exe Section loaded: msacm32.dll
Source: C:\Windows\Setup1.exe Section loaded: version.dll
Source: C:\Windows\Setup1.exe Section loaded: userenv.dll
Source: C:\Windows\Setup1.exe Section loaded: dwmapi.dll
Source: C:\Windows\Setup1.exe Section loaded: urlmon.dll
Source: C:\Windows\Setup1.exe Section loaded: mpr.dll
Source: C:\Windows\Setup1.exe Section loaded: sspicli.dll
Source: C:\Windows\Setup1.exe Section loaded: winmmbase.dll
Source: C:\Windows\Setup1.exe Section loaded: winmmbase.dll
Source: C:\Windows\Setup1.exe Section loaded: iertutil.dll
Source: C:\Windows\Setup1.exe Section loaded: srvcli.dll
Source: C:\Windows\Setup1.exe Section loaded: netutils.dll
Source: C:\Windows\Setup1.exe Section loaded: aclayers.dll
Source: C:\Windows\Setup1.exe Section loaded: sfc.dll
Source: C:\Windows\Setup1.exe Section loaded: sfc_os.dll
Source: C:\Windows\Setup1.exe Section loaded: msvbvm60.dll
Source: C:\Windows\Setup1.exe Section loaded: windows.storage.dll
Source: C:\Windows\Setup1.exe Section loaded: wldp.dll
Source: C:\Windows\Setup1.exe Section loaded: profapi.dll
Source: C:\Windows\Setup1.exe Section loaded: vb6zz.dll
Source: C:\Windows\Setup1.exe Section loaded: vb6es.dll
Source: C:\Windows\Setup1.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\Setup1.exe Section loaded: sxs.dll
Source: C:\Windows\Setup1.exe Section loaded: propsys.dll
Source: C:\Windows\Setup1.exe Section loaded: textinputframework.dll
Source: C:\Windows\Setup1.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\Setup1.exe Section loaded: coremessaging.dll
Source: C:\Windows\Setup1.exe Section loaded: ntmarta.dll
Source: C:\Windows\Setup1.exe Section loaded: wintypes.dll
Source: C:\Windows\Setup1.exe Section loaded: wintypes.dll
Source: C:\Windows\Setup1.exe Section loaded: wintypes.dll
Source: C:\Windows\Setup1.exe Section loaded: textshaping.dll
Source: C:\Windows\Setup1.exe Section loaded: vb6stkit.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: apphelp.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: acgenral.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: uxtheme.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: winmm.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: samcli.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: msacm32.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: version.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: userenv.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: dwmapi.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: urlmon.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: mpr.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: sspicli.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: winmmbase.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: winmmbase.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: iertutil.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: srvcli.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: netutils.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: aclayers.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: sfc.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: sfc_os.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: kernel.appcore.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: textinputframework.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: coreuicomponents.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: coremessaging.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: ntmarta.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: wintypes.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: wintypes.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: wintypes.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: textshaping.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: windows.storage.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: wldp.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: propsys.dll
Source: C:\Windows\ST6UNST.EXE Section loaded: profapi.dll
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
Source: RecMin_Free_Install_v_2023_r1.zip Static file information: File size 15274040 > 1048576

Persistence and Installation Behavior

barindex
Source: C:\Windows\Setup1.exe Executable created and started: C:\WINDOWS\ST6UNST.EXE
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Executable created and started: C:\WINDOWS\Setup1.exe
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Users\user\AppData\Local\Temp\msftqws.pdw\VB6STKIT.DLL Jump to dropped file
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Windows\Setup1.exe Jump to dropped file
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Windows\temp.000 Jump to dropped file
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Users\user\AppData\Local\Temp\msftqws.pdw\VB6ES.DLL Jump to dropped file
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Windows\Setup1.exe Jump to dropped file
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Windows\temp.000 Jump to dropped file
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Windows\temp.000 Jump to dropped file
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Registry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\VBRuntime
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\ST6UNST Uninstaller.LNK
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\ST6UNST Uninstaller.LNK
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\ST6UNST.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\ST6UNST.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Setup1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\ST6UNST.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\ST6UNST.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Window / User API: threadDelayed 9592
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Window / User API: threadDelayed 9838
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe TID: 932 Thread sleep count: 63 > 30
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe TID: 932 Thread sleep count: 324 > 30
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe TID: 932 Thread sleep count: 9592 > 30
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe TID: 2204 Thread sleep count: 64 > 30
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe TID: 2204 Thread sleep count: 9838 > 30
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe TID: 2204 Thread sleep count: 86 > 30
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData\Roaming
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe File opened: C:\Users\user\AppData
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\RecMin_Free_Install_v_2023_r1\setup.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\Setup1.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\Setup1.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\Setup1.exe Queries volume information: C:\ VolumeInformation
⊘No contacted IP infos