Windows Analysis Report
NeatReader Setup 8.1.4.exe

Overview

General Information

Sample name: NeatReader Setup 8.1.4.exe
Analysis ID: 1521514
MD5: def17c832c3e8169a69d3e854193f59b
SHA1: 9c0a89ea5f757e411b04cd39cae2ee77f1ea3093
SHA256: ccdc54fc8400b225b46216f3172a57433b99e78f3acb7df4ff7d4b7ab56327de
Infos:

Detection

Score: 6
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Compliance

Score: 33
Range: 0 - 100

Signatures

Contains functionality for read data from the clipboard
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
EXE planting / hijacking vulnerabilities found
Enables security privileges
Found dropped PE file which has not been started or loaded
Installs a raw input device (often for capturing keystrokes)
PE file contains sections with non-standard names
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe EXE: C:\Users\user\AppData\Local\neatreader-updater\installer.exe Jump to behavior

Compliance

barindex
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe EXE: C:\Users\user\AppData\Local\neatreader-updater\installer.exe Jump to behavior
Source: NeatReader Setup 8.1.4.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\LICENSE.electron.txt Jump to behavior
Source: NeatReader Setup 8.1.4.exe Static PE information: certificate valid
Source: NeatReader Setup 8.1.4.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: ffmpeg.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1724019640.0000000006750000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: libEGL.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1724019640.0000000006750000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: vulkan-1.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1776823382.0000000005BE0000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1776661234.0000000004C20000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: electron.exe.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1780169049.0000000007655000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: electron.exe.pdb0 source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1780169049.0000000007655000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: libGLESv2.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: libGLESv2.dll.pdbp" source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: vulkan-1.dll.pdb@ source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1776823382.0000000005BE0000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1776661234.0000000004C20000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: vk_swiftshader.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: M.pdB source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.00000000051D5000.00000004.00001000.00020000.00000000.sdmp
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_004059CC GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, 0_2_004059CC
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_004065FD FindFirstFileW,FindClose, 0_2_004065FD
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_00402868 FindFirstFileW, 0_2_00402868
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list\libs Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list\libs\darwin Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list Jump to behavior
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: * **Google Hangouts Video**: http://www.youtube.com/watch?v=I9nDOSGfwZg equals www.youtube.com (Youtube)
Source: NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp String found in binary or memory: V8.MemoryHeapUsedV8.MemoryHeapCommitted.gmail.docs.plus.inboxcalendar.google.com.calendarwww.youtube.com.youtube.top10sina.com.cnfacebook.combaidu.comqq.comtwitter.comtaobao.comlive.comwikipedia equals www.youtube.com (Youtube)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779951010.0000000006F50000.00000004.00001000.00020000.00000000.sdmp, NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp String found in binary or memory: www.youtube.com equals www.youtube.com (Youtube)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/1085
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/1452
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/1452expand_integer_pow_expressionsThe
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/1512
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/1637
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/1936
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2046
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2152
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2152skip_vs_constant_register_zeroIn
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2273
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2517
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2970
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2978
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3016
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3027
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3045
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3246
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3246allow_clear_for_robust_resource_initSome
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3682
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3682GL_USES_FRAG_COLORGL_USES_FRAG_DATA_SECONDARY_COLORGL_USES_SECONDARGL_USES_F
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3729
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3859
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3970
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3997
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4214
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4267
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4646
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/482
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5007
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5007disable_anisotropic_filteringDisable
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5469
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5750
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5750ANGLE_DEFAULT_PLATFORMvulkanvulkan-nullswiftshadergld3d11GPU.ANGLE.DisplayIn
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://blog.izs.me
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://blog.izs.me/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://blog.izs.me/)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://certificates.starfieldtech.com/repository/0
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://certificates.starfieldtech.com/repository/sfig2.crt0
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://certs.starfieldtech.com/repository/1402
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/1094869
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/110263
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/1144207
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/1165751
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/1165751Disable
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/1171371
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/308366
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/403957
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/565179
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/642227
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/642605
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/644669
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/650547
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/672380
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/709351
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/772651
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/797243
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/809422
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/830046
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/849576
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/883276
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/927470
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/941620
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/941620allow_translate_uniform_block_to_structured_bufferThere
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://creativecommons.org/publicdomain/zero/1.0/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://crl.starfieldtech.com/sfig2s5-0.crl0c
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://crl.starfieldtech.com/sfroot-g2.crl0L
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://debuggable.com/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ecma-international.org/ecma-262/7.0/#sec-ecmascript-function-objects-call-thisargument-argume
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ecma-international.org/ecma-262/7.0/#sec-object.keys)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ecma-international.org/ecma-262/7.0/#sec-object.prototype.tostring)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ecma-international.org/ecma-262/7.0/#sec-patterns).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ecma-international.org/ecma-262/7.0/#sec-properties-of-the-map-prototype-object)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ecma-international.org/ecma-262/7.0/#sec-samevaluezero)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ecma-international.org/ecma-262/7.0/#sec-template-literal-lexical-components).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ecma-international.org/ecma-262/7.0/#sec-tolength).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://eev.ee/blog/2015/09/12/dark-corners-of-unicode/).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ejohn.org/blog/javascript-micro-templating/)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1780169049.0000000007450000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://feross.org
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/00e8f7a1b7603aabdb7fb3567f485cb1c2076702)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/0251b38a8405471892c5eeaba7c8d54bd7028214)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/04e07fdc620841068f12b8edf36f27e6592a0a18)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/12960c437cc25c53e682cfe5bff06d74a5bb1eb9)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/130e363856747b487652f04b5550056d7778e43a)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/132c9ee63f92a586a120ed3bd6b7ef023badb8bb)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/2180839eda2cb16edcfda46ccfe24711680af850)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/219bf22237b11bc375e2e110b93db512f1acfdd4)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/23f7f545abfe1fb6499cd61cc8ff41fd86cef4a0)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/287e589ac773d3738b2aa7d40e0b6d43dde5261b)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/2c86b10feafd868ebd071dda3a222e6f51972b5d)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/2d1c5981869e0fe6f5bc71b5c5582accfd125cc6)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/2ee32f50b88b383317e33cc0a4bfaa5f2eadead7)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/2f2078bf998bd3f44289ebd17eeccf5e12e4c134)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/325792aee92de0ba6fea306657933fc63dc00474)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/3b23865340cfba075f61f7dba0ea31fcc27260ec)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/422e539e8989e65ba43ecc39ddbaa3c4f755d465)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/48993ade9b0831fbce28d94b3b0963a4b0dccbdd)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/49642428342e5f291eb9d690802e83ed830623b5)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/4dc56f6d04e8f5fe12ba53a8a776653b3d7b60ed)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/4f968298f97394e488297ec32c8e927a3a322076)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/52a673703a87a93c0f6a8552e6bd73caba66d2eb)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/54e8fab3e3d907bbb264caf3e28a24773d0d6fdb)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/5560f729124f022ffed00085aafea43dded7fb03)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/5810f279a4caeda115f39e429c9671795613abf8)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/5afff89eca0efe7081309dc2d123309e825df221)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/62f29eb0c4dee01170a5511615e5bcc9faca26ca)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/71aaa29591d6681f8579486f18d32ba1ee651a5b)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/72f325b78edd0dc2aac940a76ce5f644005ce4c3)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/75233d974a30af6e3b8ab38a73e5ede67172fc1c)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/7e46c2058cb5994809eab5f4dbb12f21e937c72b)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/817b49830571b45a8aec6b1fc1525434f5798c58)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/88b92b43153f21609aee71d47abcd4dc27a6586d)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/8be5626bbb54e6c899a1b71d22411709126d9fea)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/9146024e1094e8bb871ab15d1b7fc556a710732f)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/99051992a9f45eb0dd79e062681d6f5d366deb41)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/9be858312553002841725b617050aaff3c48951d)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/9c5c58b18363494976185e7ddc790ac63de840ed)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/a007198fa23c19902b1f3ffb81498629e0e9c875)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/a245d18a131341feec4f87659746954e78cae780)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/acb388bc0546b48fca11dce8aa7a595af2cda5e2)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/ad91ce2346cb34e5d5a49d07dd952d15f6c832a3)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/b15115b2cbfffe15827cd5e4368267d417b72f08)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/b25e79dfb599777a38157bd419395bd28369ee86)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/b7bfa7113b8d1af49a57ab767f24a599ed92044f)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/b7fc526ea49894f366153bd32997e02568c0b8a6)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/b968688afe2c727ae141f50aa983d481dbc1dbbf)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/b9e35469d3bbd0a1ee92e0a815ce2512904d4a18)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/bc81ca9414296234c764b7306a19ba72b2e59b52)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/be7d334778481639294cdf87f5c359a230aeb65b)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/cf70dbc6d2ba62bf1eb12b563dd5ecd27af6e2be)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/d1d65dd29d7bbaf9ea42eaa5fcb0da3fb4df98e9)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/d32623baa7a6273d47be67d587ad4ea0ecffc5de)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/d48d88ee17b780c02123e6d657274cab456e943e)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/d4bdb5ed9e2fe06ec44698b66c029f624135a0ab)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/d7f7f77689e2eaef050686be2bdf3e72881a79ac)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/d9ef60398e88f2c2f958ab2b159d38052ffe7f8a)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/ef5c43bcbcf31819e032c3b7ae7654b7f8e9358b)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/f155785e2bb42b5ddf0a8156401c6dafdf57ba8b)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/f75d4455359ecdf30eeb676e2c7f31d4cf7b42ed)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/f90e825da9d505c11b4262c50cd54553f979c300)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/fc93c05f68398f30abc46fd16ae6c673a1eee099)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/koajs/koa/commit/ff70bdc75a30a37f63fc1f7d8cbae3204df3d982)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/node-modules/ylru/commit/475abb0e9c787fd65d7c3dd3d2d74d67560b0bec)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/oozcitak/xmlbuilder-js
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/qix-
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/substack/js-traverse.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://github.com/visionmedia/expresso
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://google.com
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://jedschmidt.com)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://jongleberry.com
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://jquery.org/license
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://jsperf.com/javascript-array-concat-vs-push/98
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ljharb.codes
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://mathiasbynens.be/notes/javascript-encoding#surrogate-formulae
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://mths.be/fromcodepoint
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://n8.io/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000000.1663626184.000000000040A000.00000008.00000001.01000000.00000003.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000040A000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://ocsp.digicert.com0A
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://ocsp.digicert.com0C
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://ocsp.digicert.com0X
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://ocsp.starfieldtech.com/0;
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: http://ocsp.starfieldtech.com/0F
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://paul.vorba.ch
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://peter.michaux.ca/articles/lazy-function-definition-pattern)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://requirejs.org/docs/errors.html#mismatch
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://stackoverflow.com/a/1068308/13216
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://stackoverflow.com/a/16459606/376773
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://stackoverflow.com/a/398120/376773
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://stackoverflow.com/a/5982798/376773
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://substack.net
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://substack.net)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://underscorejs.org/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://underscorejs.org/LICENSE
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://unisolated.invalid
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://unisolated.invalidsms_fetcherBlink.Sms.Receive.TimeSmsReceiveBlink.Sms.Receive.TimeCancelOnSu
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://wonko.com/post/html-escaping)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.another-d-mention.ro/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720531963.0000000006B50000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1779951010.0000000006F50000.00000004.00001000.00020000.00000000.sdmp, NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ecma-international.org/ecma-262/7.0/#sec-ecmascript-language-types)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ecma-international.org/ecma-262/7.0/#sec-function.prototype.apply).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ecma-international.org/ecma-262/7.0/#sec-regexp.prototype.tostring
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ecma-international.org/ecma-262/7.0/#sec-tointeger).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.html5rocks.com/en/tutorials/developertools/sourcemaps/#toc-sourceurl)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.opensource.org/licenses/mit-license.php
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1704965260.0000000005D60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.unicode.org/copyright.html
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.whatwg.org/specs/web-apps/current-work/multipage/comms.html#crossDocumentMessages
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.youtube.com/watch?v=I9nDOSGfwZg
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/4674
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/4849
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/5140
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.chromium.org/p/chromium/issues/detail?id=378607
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.chromium.org/p/chromium/issues/detail?id=449857
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.chromium.org/p/chromium/issues/detail?id=470258
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.chromium.org/p/chromium/issues/detail?id=589347
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.chromium.org/p/v8/issues/detail?id=2070)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.chromium.org/p/v8/issues/detail?id=90
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.jquery.com/ticket/12359
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.jquery.com/ticket/13378
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.webkit.org/show_bug.cgi?id=136851
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.webkit.org/show_bug.cgi?id=137337
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.webkit.org/show_bug.cgi?id=156034
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugs.webkit.org/show_bug.cgi?id=29084
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=687787
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: https://certs.starfieldtech.com/repository/0
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome-devtools-frontend.appspot.com/serve_rev/%s/%s.html
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome-devtools-frontend.appspot.com/serve_rev/%s/%s.html/devtools/page/%s?ws=%s%s%sMalforme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chromium.googlesource.com/angle/angle/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crashpad.chromium.org/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crashpad.chromium.org/bug/new
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crashpad.chromium.org/https://crashpad.chromium.org/bug/new
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/1042393
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/1046462
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/1091824
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/1137851
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/401439).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/593024
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/593024select_view_in_geometry_shaderThe
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/650547
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/650547call_clear_twiceUsing
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/655534
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/655534use_system_memory_for_constant_buffersCopying
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/705865
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/710443
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/811661
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://css-tricks.com/debouncing-throttling-explained-examples/)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://developer.chrome.com/extensions/sandboxingEval).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/docs/CSS/display
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en-US/docs/Tools/Web_Console#Styling_messages
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://developer.mozilla.org/en/DOM/window.postMessage
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/document/d/17aTgLnjMXIrfjgNaTUnHQO7m3xgzHR2VXBTmi03Qii4/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://drafts.csswg.org/cssom/#common-serializing-idioms
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://drafts.csswg.org/cssom/#resolved-values
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://es5.github.io/#x13.2.2
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://es5.github.io/#x15.1.2.2)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/3rd-Eden/kuler
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/3rd-Eden/kuler.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/3rd-Eden/text-hex
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/3rd-Eden/text-hex.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000002.1852089016.000000000041E000.00000004.00000001.01000000.00000003.sdmp String found in binary or memory: https://github.com/Gauzytech/NeatReaderDeskAppPackager0
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/Leonidas-from-XIV/node-xml2js
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/Leonidas-from-XIV/node-xml2js.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/RyanZim/universalify#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/RyanZim/universalify.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/TooTallNate/util-deprecate
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/WebReflection/get-own-property-symbols/issues/4
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/YuzuJS/setImmediate#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/YuzuJS/setImmediate.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/ZJONSSON/node-unzipper#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/ZJONSSON/node-unzipper.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/alessioalex/tiny-each-async#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/alessioalex/tiny-each-async.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/antelle
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/antelle/node-stream-zip
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/antelle/node-stream-zip.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/antelle/node-stream-zip/blob/master/LICENSE
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/bnjmnt4n/lodash-cli.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/calvinmetcalf/process-nextick-args
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/calvinmetcalf/process-nextick-args.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/component/toidentifier#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/component/toidentifier.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/crypto-utils/keygrip#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/crypto-utils/keygrip.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/cthackers/adm-zip
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/dougwilson/nodejs-depd#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/dougwilson/nodejs-depd.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/es-shims/String.prototype.trimEnd#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/es-shims/String.prototype.trimStart#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/es-shims/es5-shim
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/es-shims/es6-shim
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/es-shims/object.getownpropertydescriptors#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/eslint/eslint/issues/3229
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/eslint/eslint/issues/6125
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/expressjs/vary)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/facebook/react-native/pull/1632
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/felixge/node-stack-trace
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/feross/safe-buffer
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/golang/go/blob/master/src/archive/zip/reader.go#L503
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/gyson/koa-convert#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/gyson/koa-convert.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/hgouveia/node-downloader-helper
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/hgouveia/node-downloader-helper.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/hgouveia/node-downloader-helper/issues)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/inspect-js/object-inspect
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/inspect-js/which-boxed-primitive#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/inspect-js/which-boxed-primitive.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/iojs/readable-stream/issues/101)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/iojs/readable-stream/issues/102)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/iojs/readable-stream/issues/105)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/iojs/readable-stream/issues/106
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/iojs/readable-stream/issues/99)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/iojs/readable-stream/labels/wg-agenda
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/isaacs/inherits#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/isaacs/minimatch#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/isaacs/once#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/isaacs/sax-js#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jashkenas/underscore/pull/1247
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jden/node-listenercount#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/joyent/node
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/joyent/node/pull/7878
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jprichardson/node-jsonfile#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jquery/jquery
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jquery/jquery.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jquery/jquery/blob/3.2.1/AUTHORS.txt
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jquery/jquery/pull/557)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jquery/sizzle
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jquery/sizzle/pull/225
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries#wiki-anon
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/basic-auth/issues/39
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/http-assert
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/http-errors
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/http-errors#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/http-errors.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/media-typer#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/media-typer.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/mime-db#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/mime-db.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/mime-types#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/mime-types.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/negotiator#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/negotiator.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/on-finished#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/on-finished.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/statuses#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/statuses.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/type-is#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/type-is.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/vary#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/jshttp/vary.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/compose#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/compose.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/compose/blob/4e3e96baf58b817d71bd44a8c0d78bb42623aa95/index.js#L36
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/compose/pull/27
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/compose/pull/61
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/compose/pull/65
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/json)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/koa#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/koa.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/koa/blob/master/docs/error-handling.md
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/koa/blob/master/docs/migration.md
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/koa/pull/438).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/koa/pull/614
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/koa/pull/668
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/koajs.com/pull/38.
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/send
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/static#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/koajs/static.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/ljharb/object-keys#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/ljharb/object.assign#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/ljharb/object.assign/issues/17
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/ljharb/unbox-primitive#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/ljharb/unbox-primitive.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/ljharb/util.promisify#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/ljharb/util.promisify.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/lodash/lodash
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/lodash/lodash.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/lodash/lodash/blob/4.17.15/dist/lodash.js#L6735-L6744
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/node-modules/ylru
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/TSC/blob/master/Moderation-Policy.md
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/blob/b1c8f15c5f169e021f7c46eb7b219de95fe97603/lib/util.js#L201-L230
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/blob/b3fcc245fb25539909ef1d5eaa01dbf92e168633/lib/path.js#L56
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/blob/master/CODE_OF_CONDUCT.md
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/blob/v4.4.7/lib/_http_server.js#L486
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/issues/3043
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/node/pull/3073
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/readable-stream#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/nodejs/string_decoder
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/npm/wrappy
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/npm/wrappy.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/olado/doT).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/pillarjs/parseurl#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/pillarjs/parseurl.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/pillarjs/resolve-path#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/pillarjs/resolve-path.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/pvorb/node-md5#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/qix-/node-simple-swizzle#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/qix-/node-simple-swizzle.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/sindresorhus/path-is-absolute#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/sindresorhus/path-is-absolute.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/sindresorhus/time-zone#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/sindresorhus/time-zone.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/sponsors/ljharb
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/substack/js-traverse#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/substack/minimist
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/substack/node-hashish).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/substack/node-mkdirp.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/suryagh/tsscmp#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/suryagh/tsscmp.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/unshiftio/one-time#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/unshiftio/one-time.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/vercel/ms#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/vercel/ms.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/visionmedia/debug#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/visionmedia/node-only#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/wesleytodd/setprototypeof
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/wesleytodd/setprototypeof.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/logform#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/logform.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/triple-beam#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/triple-beam.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/winston#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/winston-transport#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/winston.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/winston/blob/2.x/lib/winston/logger.js#L198-L201
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/winston/blob/master/UPGRADE-3.0.md
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/winstonjs/winston/tree/master/UPGRADE-3.0.md
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/zeit/ms#readme
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/zeit/ms.git
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://goo.gl/yabPex
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://guides.github.com/activities/contributing-to-open-source/).MIT
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/#strip-and-collapse-whitespace
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/forms.html#category-listed
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/forms.html#concept-fe-disabled
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/forms.html#concept-option-disabled
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/infrastructure.html#space-character
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/infrastructure.html#strip-and-collapse-whitespace
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/scripting.html#selector-disabled
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/scripting.html#selector-enabled
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/syntax.html#attributes-2
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://jquery.com
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://jquery.com/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://jquery.org/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://jquery.org/license
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://js.foundation/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://jsperf.com/getall-vs-sizzle/2
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://jsperf.com/thor-indexof-vs-for/5
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://lodash.com/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://lodash.com/)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://lodash.com/custom-builds).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://lodash.com/icon.svg
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://lodash.com/license
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mathiasbynens.be/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mathiasbynens.be/notes/ambiguous-ampersands)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.000000000520A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mathiasbynens.be/notes/javascript-unicode).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/Array/reverse).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/Array/slice)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/Number/isFinite).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/Number/isInteger).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/Number/isNaN)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/Number/isSafeInteger).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/Object/assign).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/String/replace).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/String/split).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/Structured_clone_algorithm)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/clearTimeout).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/isNaN)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/iteration_protocols#iterator).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/rest_parameters).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/round#Examples)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/setTimeout).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/spread_operator).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/toLowerCase).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mdn.io/toUpperCase).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://monitoring.url.loader.factory.invalid
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://monitoring.url.loader.factory.invalidPermissions
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://mths.be/he).
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://nodejs.org/api/http.html#http_response_writableended
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://nodejs.org/api/stream.html#stream_readable_pipe_destination_options
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://npms.io/search?q=ponyfill.
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://openjsf.org/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://pkware.cachefly.net/webdocs/casestudies/APPNOTE.TXT
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://promisesaplus.com/#point-48
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://promisesaplus.com/#point-54
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://promisesaplus.com/#point-57
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://promisesaplus.com/#point-59
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://promisesaplus.com/#point-61
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://promisesaplus.com/#point-64
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://promisesaplus.com/#point-75
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://raw.githubusercontent.com/cthackers/adm-zip/master/LICENSE
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://registry.npmjs.org
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://sizzlejs.com/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://stackoverflow.com/questions/16254385/undocumented-response-finished-in-node-js
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://w3c.github.io/encrypted-media/#direct-individualization.
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://w3c.github.io/encrypted-media/#distinctive-identifier)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://w3c.github.io/encrypted-media/#distinctive-permanent-
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://web.archive.org/web/20100324014747/http://blindsignals.com/index.php/2009/07/jquery-delay/
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://web.archive.org/web/20141116233347/http://fluidproject.org/blog/2008/01/09/getting-setting-a
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/feature/5148698084376576
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/feature/5669008342777856
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/feature/5709390967472128
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/feature/5742188281462784.
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/feature/5742188281462784.CancelDeferredNavigationWillFailRequestDidComm
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.chromium.org/blink/origin-trials/portals
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.chromium.org/blink/origin-trials/portalsPrerenderHost::StartPrerenderingrender_frame_hos
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google./_/chrome/plus.google.cominbox.google.comdrive.google.comServiceWorker.DiskCache.
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/speech-api/full-duplex/v1
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/speech-api/full-duplex/v1key=pair=output=pb/down?speech_recognition_downstrea
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/geolocation/v1/geolocate
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/geolocation/v1/geolocatemacAddresssignalStrengthsignalToNoiseRatiowifiAcc
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.gstatic.com/securitykey/a/google.com/origins.json
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.gstatic.com/securitykey/origins.json
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006B50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.gstatic.com/securitykey/origins.jsonhttps://www.gstatic.com/securitykey/a/google.com/ori
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2011/february/double-hmac-verificati
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.npmjs.com/package/babel-polyfill)
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1720136744.0000000005960000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://xivilization.net
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_00405461 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard, 0_2_00405461
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1780169049.0000000007450000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: RegisterRawInputDevices() failed for RIDEV_REMOVE memstr_409e7262-1
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_100010D0 GetVersionExW,LoadLibraryW,GetProcAddress,LocalAlloc,LocalAlloc,NtQuerySystemInformation,LocalFree,LocalAlloc,FreeLibrary,lstrcpynW,lstrcmpiW,LocalFree,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,lstrlenW,lstrlenA,MultiByteToWideChar,lstrcmpiW,CloseHandle,FreeLibrary, 0_2_100010D0
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_0040338F EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,ExitProcess,CoUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_0040338F
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_00406B15 0_2_00406B15
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_004072EC 0_2_004072EC
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_00404C9E 0_2_00404C9E
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Process token adjusted: Security Jump to behavior
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevk_swiftshader.dll, vs NeatReader Setup 8.1.4.exe
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibGLESv2.dllb! vs NeatReader Setup 8.1.4.exe
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006D57000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: ../../base/file_version_info_win.ccCreateFileVersionInfoWinCompanyNameCompanyShortNameInternalNameProductNameProductShortNameProductVersionFileDescriptionFileVersionOriginalFilenameSpecialBuild\StringFileInfo\%04x%04x\%ls\VarFileInfo\Translation\../../base/files/file_path_watcher_win.ccUpdateWatchDestroyWatchSetupWatchHandleOnObjectSignaled( vs NeatReader Setup 8.1.4.exe
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1724019640.0000000006750000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibEGL.dllb! vs NeatReader Setup 8.1.4.exe
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1724019640.0000000006750000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamed3dcompiler_47.dllj% vs NeatReader Setup 8.1.4.exe
Source: NeatReader Setup 8.1.4.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: clean6.winEXE@12/130@0/0
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_0040338F EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,ExitProcess,CoUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_0040338F
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_00404722 GetDlgItem,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW, 0_2_00404722
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_00402104 CoCreateInstance, 0_2_00402104
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Users\user\AppData\Local\neatreader-updater Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\AtomProcessSingletonStartup!
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Mutant created: NULL
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Mutant created: \Sessions\1\BaseNamedObjects\bbff271c-caf8-5302-b3c6-6d9ee38f27e3
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Users\user\AppData\Local\Temp\nsbD873.tmp Jump to behavior
Source: NeatReader Setup 8.1.4.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779951010.0000000006F50000.00000004.00001000.00020000.00000000.sdmp, NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1780169049.0000000007655000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: SELECT name FROM sqlite_master WHERE type='table';
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779951010.0000000006F50000.00000004.00001000.00020000.00000000.sdmp, NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779951010.0000000006F50000.00000004.00001000.00020000.00000000.sdmp, NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779951010.0000000006F50000.00000004.00001000.00020000.00000000.sdmp, NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779951010.0000000006F50000.00000004.00001000.00020000.00000000.sdmp, NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779951010.0000000006F50000.00000004.00001000.00020000.00000000.sdmp, NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File read: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe "C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe"
Source: unknown Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe"
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\NeatReader /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\NeatReader\Crashpad --url=http://localhost:9000 "--annotation=_companyName=Gauzy Tech" "--annotation=_productName=NeatReader Desk App" --annotation=_version=8.1.4 --annotation=prod=Electron --annotation=ver=13.0.1 --initial-client-data=0x47c,0x480,0x484,0x474,0x488,0x6df17c0,0x6df17d0,0x6df17dc
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=gpu-process --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1560 /prefetch:2
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2436 /prefetch:8
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --lang=en-GB --app-path="C:\Program Files (x86)\NeatReader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2536 /prefetch:1
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --disable-gpu-compositing --lang=en-GB --app-path="C:\Program Files (x86)\NeatReader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3064 /prefetch:1
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\NeatReader /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\NeatReader\Crashpad --url=http://localhost:9000 "--annotation=_companyName=Gauzy Tech" "--annotation=_productName=NeatReader Desk App" --annotation=_version=8.1.4 --annotation=prod=Electron --annotation=ver=13.0.1 --initial-client-data=0x47c,0x480,0x484,0x474,0x488,0x6df17c0,0x6df17d0,0x6df17dc Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=gpu-process --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1560 /prefetch:2 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2436 /prefetch:8 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --lang=en-GB --app-path="C:\Program Files (x86)\NeatReader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2536 /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --disable-gpu-compositing --lang=en-GB --app-path="C:\Program Files (x86)\NeatReader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3064 /prefetch:1 Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: windows.fileexplorer.common.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: ffmpeg.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: kbdus.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: windows.ui.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: windowmanagementapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: inputhost.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mmdevapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: devobj.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mscms.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: coloradapterclient.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: windows.globalization.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: twinapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: atlthunk.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: directmanipulation.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msspellcheckingfacility.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: cryptnet.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: ffmpeg.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: ffmpeg.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mf.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mfplat.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: rtworkq.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msmpeg2vdec.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dxva2.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msvproc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: d3dcompiler_47.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: d3dcompiler_47.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: comppkgsup.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mfh264enc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: windows.media.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: ffmpeg.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: kbdus.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: ffmpeg.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: ffmpeg.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32 Jump to behavior
Source: NeatReader.lnk.0.dr LNK file: ..\..\..\..\..\Program Files (x86)\NeatReader\NeatReader.exe
Source: NeatReader.lnk0.0.dr LNK file: ..\..\..\Program Files (x86)\NeatReader\NeatReader.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: NeatReader Setup 8.1.4.exe Static PE information: certificate valid
Source: NeatReader Setup 8.1.4.exe Static file information: File size 62455064 > 1048576
Source: NeatReader Setup 8.1.4.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: ffmpeg.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1724019640.0000000006750000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: libEGL.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1724019640.0000000006750000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: vulkan-1.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1776823382.0000000005BE0000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1776661234.0000000004C20000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: electron.exe.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1780169049.0000000007655000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: electron.exe.pdb0 source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1780169049.0000000007655000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: libGLESv2.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: libGLESv2.dll.pdbp" source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: vulkan-1.dll.pdb@ source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1776823382.0000000005BE0000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp, NeatReader Setup 8.1.4.exe, 00000000.00000003.1776661234.0000000004C20000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: vk_swiftshader.dll.pdb source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779355683.0000000006750000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: M.pdB source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1719831252.00000000051D5000.00000004.00001000.00020000.00000000.sdmp
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_100010D0 GetVersionExW,LoadLibraryW,GetProcAddress,LocalAlloc,LocalAlloc,NtQuerySystemInformation,LocalFree,LocalAlloc,FreeLibrary,lstrcpynW,lstrcmpiW,LocalFree,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,lstrlenW,lstrlenA,MultiByteToWideChar,lstrcmpiW,CloseHandle,FreeLibrary, 0_2_100010D0
Source: vulkan-1.dll.0.dr Static PE information: section name: .00cfg
Source: vulkan-1.dll.0.dr Static PE information: section name: .voltbl
Source: ffmpeg.dll.0.dr Static PE information: section name: .00cfg
Source: ffmpeg.dll.0.dr Static PE information: section name: .voltbl
Source: libEGL.dll.0.dr Static PE information: section name: .00cfg
Source: libEGL.dll.0.dr Static PE information: section name: .voltbl
Source: libGLESv2.dll.0.dr Static PE information: section name: .00cfg
Source: libGLESv2.dll.0.dr Static PE information: section name: .voltbl
Source: NeatReader.exe.0.dr Static PE information: section name: .00cfg
Source: NeatReader.exe.0.dr Static PE information: section name: .rodata
Source: NeatReader.exe.0.dr Static PE information: section name: .voltbl
Source: NeatReader.exe.0.dr Static PE information: section name: CPADinfo
Source: libEGL.dll0.0.dr Static PE information: section name: .00cfg
Source: libEGL.dll0.0.dr Static PE information: section name: .voltbl
Source: libGLESv2.dll0.0.dr Static PE information: section name: .00cfg
Source: libGLESv2.dll0.0.dr Static PE information: section name: .voltbl
Source: vk_swiftshader.dll.0.dr Static PE information: section name: .00cfg
Source: vk_swiftshader.dll.0.dr Static PE information: section name: .voltbl
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\d3dcompiler_47.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\swiftshader\libGLESv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\StdUtils.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\nsProcess.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\WinShell.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\nsis7z.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\ffmpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\libEGL.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\NeatReader.exe Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\vulkan-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Users\user\AppData\Local\neatreader-updater\installer.exe Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\resources\elevate.exe Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\SpiderBanner.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\Uninstall NeatReader.exe Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\libGLESv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\vk_swiftshader.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\swiftshader\libEGL.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\Program Files (x86)\NeatReader\LICENSE.electron.txt Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeatReader.lnk Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Program Files (x86)\NeatReader\swiftshader\libGLESv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\StdUtils.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\nsProcess.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\nsis7z.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\WinShell.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Program Files (x86)\NeatReader\libEGL.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Program Files (x86)\NeatReader\vulkan-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Program Files (x86)\NeatReader\resources\elevate.exe Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\SpiderBanner.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Program Files (x86)\NeatReader\Uninstall NeatReader.exe Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Program Files (x86)\NeatReader\libGLESv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Program Files (x86)\NeatReader\vk_swiftshader.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Program Files (x86)\NeatReader\swiftshader\libEGL.dll Jump to dropped file
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsmD94F.tmp\System.dll Jump to dropped file
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\d0010809 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\d0010809 Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe File Volume queried: C:\Users\user\AppData\Roaming\NeatReader\blob_storage\626fbe4f-8fa8-4fe4-8064-ab57ee09eed8 FullSizeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe File Volume queried: C:\Users\user\AppData\Roaming\NeatReader\Code Cache\js FullSizeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe File Volume queried: C:\Users\user\AppData\Roaming\NeatReader\Code Cache\wasm FullSizeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe File Volume queried: C:\Users\user\AppData\Roaming\NeatReader\Cache FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_004059CC GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, 0_2_004059CC
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_004065FD FindFirstFileW,FindClose, 0_2_004065FD
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_00402868 FindFirstFileW, 0_2_00402868
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list\libs Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list\libs\darwin Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe File opened: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list Jump to behavior
Source: NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: VMware Virtual Webcam
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1724019640.0000000006750000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: vmncVMware Screen Codec / VMware Videovp5On2 VP5vp6On2 VP6vp6fOn2 VP6 (Flash version)targaTruevision Targa imageimage/x-targaimage/x-tgav
Source: NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: eb1a:2860eb1a:28201ce6:282012ab:03801943:22530c45:64d00c45:64d21bcf:298504ca:704704ca:704804f2:b3ed04f2:b3ca05c8:035d05c8:036904ca:709513d3:52570bda:57f2VMware Virtual WebcamMedia.VideoCapture.BlacklistedDeviceGoogle Camera AdapterIP Camera [JPEG/MJPEG]CyberLink Webcam SplitterEpocCamWebcamMax../../media/capture/video/video_capture_metrics.ccDevice supports Media.VideoCapture.Device.SupportedPixelFormatMedia.VideoCapture.Device.SupportedResolution
Source: NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: VMnet
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: Adreno (TM) 418Adreno (TM) 530Adreno (TM) 540GL_EXT_texture_lod_biasARB_draw_buffersGL_ARB_texture_swizzleGL_EXT_texture_swizzleGL_ARB_pixel_buffer_objectGL_EXT_pixel_buffer_objectGL_EXT_draw_buffers2GL_ARB_fragment_shaderGL_NV_texture_border_clampGL_ARB_robust_buffer_access_behaviorGL_EXT_framebuffer_sRGBGL_ARB_framebuffer_sRGBfunctions->standard == STANDARD_GL_DESKTOP && isAMDfunctions->standard == STANDARD_GL_DESKTOP && isIntelisIntel && !IsSandyBridge(device) && !IsIvyBridge(device) && !IsHaswell(device)IsApple() && isIntelisIntel && IsApple() && IsSkylake(device) && GetMacOSVersion() < OSVersion(10, 13, 2)functions->standard == STANDARD_GL_DESKTOP && (isIntel || isAMD)IsLinux() && functions->standard == STANDARD_GL_DESKTOP && isAMD(IsApple() && functions->standard == STANDARD_GL_DESKTOP) || (IsLinux() && isAMD)IsApple() && functions->standard == STANDARD_GL_DESKTOP && GetMacOSVersion() < OSVersion(10, 11, 0)IsApple() && isIntel && GetMacOSVersion() < OSVersion(10, 12, 0)IsApple() && isAMDIsAndroid() && isQualcommfunctions->standard == STANDARD_GL_DESKTOP && isNvidiaIsApple() || isNvidiafunctions->isAtMostGL(gl::Version(4, 1)) || (functions->standard == STANDARD_GL_DESKTOP && isAMD)isAMD || IsAndroid()IsAndroid() || isNvidia(IsAndroid() && isQualcomm) || (isIntel && IsApple())isAMD || isIntelIsNexus5X(vendor, device)IsAndroid() || (IsWindows() && isIntel)(IsWindows() && (isIntel || isAMD)) || (IsLinux() && isNvidia) || IsIOS() || IsAndroidEmulator(functions)IsAndroid() || limitMaxTextureSizeIsAndroid() || (IsApple() && (isIntel || isAMD || isNvidia))limitMaxTextureSizeIsApple()IsAndroid() || isAMD || !functions->hasExtension("GL_KHR_robust_buffer_access_behavior")IsApple() && isIntel && GetMacOSVersion() >= OSVersion(10, 12, 4)IsApple() && isIntel && GetMacOSVersion() < OSVersion(10, 12, 6)IsLinux() || (IsAndroid() && isNvidia) || (IsWindows() && isNvidia) || (IsApple() && functions->standard == STANDARD_GL_ES)IsApple() || (IsLinux() && isAMD)IsApple() || (IsWindows() && isAMD)functions->standard == STANDARD_GL_DESKTOP && functions->isAtLeastGL(gl::Version(3, 1)) && !functions->isAtLeastGL(gl::Version(4, 3))features->emulatePrimitiveRestartFixedIndex.enabled && IsApple() && isIntelIsApple() || IsAndroid() || IsWindows()functions->standard == STANDARD_GL_ES && functions->isAtLeastGLES(gl::Version(3, 1)) && functions->hasGLESExtension("GL_EXT_texture_norm16")IsWindows() && isAMDIsLinux() && isAMD && isMesa && mesaVersion < (std::array<int, 3>{19, 3, 5})(IsLinux() && isVMWare) || (IsAndroid() && isNvidia) || (IsAndroid() && GetAndroidSdkLevel() < 27 && IsAdreno5xxOrOlder(functions)) || (IsAndroid() && IsMaliT8xxOrOlder(functions)) || (IsAndroid() && IsMaliG31OrOlder(functions))IsApple() && functions->standard == STANDARD_GL_ES && !(isAMD && IsWindows())isDualGPUMacWithNVIDIAisTSANBuild && IsLinux() && isNvidiaIsApple() && (isAMD || isIntel || isNvidia)IsLinux() && IsWayland()!CanMapBufferForRead(functions)IsApple() && hasAMDIsAdreno42xOr3xx(func
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1726722266.0000000006B50000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: (IsLinux() && isVMWare) || (IsAndroid() && isNvidia) || (IsAndroid() && GetAndroidSdkLevel() < 27 && IsAdreno5xxOrOlder(functions)) || (IsAndroid() && IsMaliT8xxOrOlder(functions)) || (IsAndroid() && IsMaliG31OrOlder(functions))
Source: NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: num_failuresrelease_after_msThrottling.RequestThrottled%08x: %02x ../../net/base/network_interfaces_win.ccWlanApiwlanapi.dllWlanQueryInterfaceWlanSetInterfaceVMnetGetAdaptersAddresses failed:
Source: NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: lgnW2/4/PEZB31jiVg88O8EckzXZOFKs7sjsLjBOlDW0JB9LeGna8gI4zJVSk/BwJVmcIGfE
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1724019640.0000000006750000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: VMware Screen Codec / VMware Video
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_100010D0 GetVersionExW,LoadLibraryW,GetProcAddress,LocalAlloc,LocalAlloc,NtQuerySystemInformation,LocalFree,LocalAlloc,FreeLibrary,lstrcpynW,lstrcmpiW,LocalFree,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,lstrlenW,lstrlenA,MultiByteToWideChar,lstrcmpiW,CloseHandle,FreeLibrary, 0_2_100010D0
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\NeatReader /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\NeatReader\Crashpad --url=http://localhost:9000 "--annotation=_companyName=Gauzy Tech" "--annotation=_productName=NeatReader Desk App" --annotation=_version=8.1.4 --annotation=prod=Electron --annotation=ver=13.0.1 --initial-client-data=0x47c,0x480,0x484,0x474,0x488,0x6df17c0,0x6df17d0,0x6df17dc Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=gpu-process --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1560 /prefetch:2 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2436 /prefetch:8 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --lang=en-GB --app-path="C:\Program Files (x86)\NeatReader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2536 /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "C:\Program Files (x86)\NeatReader\NeatReader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,SameSiteByDefaultCookies,SpareRendererForSitePerProcess --disable-gpu-compositing --lang=en-GB --app-path="C:\Program Files (x86)\NeatReader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3064 /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=crashpad-handler --user-data-dir=c:\users\user\appdata\roaming\neatreader /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler --database=c:\users\user\appdata\roaming\neatreader\crashpad --url=http://localhost:9000 "--annotation=_companyname=gauzy tech" "--annotation=_productname=neatreader desk app" --annotation=_version=8.1.4 --annotation=prod=electron --annotation=ver=13.0.1 --initial-client-data=0x47c,0x480,0x484,0x474,0x488,0x6df17c0,0x6df17d0,0x6df17dc
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=gpu-process --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=cookieswithoutsamesitemustbesecure,samesitebydefaultcookies,sparerendererforsiteperprocess --gpu-preferences=saaaaaaaaadgaaawaaaaaaaaaaaaaaaaaabgaaaaaaaoaaaaaaaaaaaaaaaaaaaaaaaaaaaaaab4aaaaaaaaahgaaaaaaaaakaaaaaqaaaagaaaaaaaaacgaaaaaaaaamaaaaaaaaaa4aaaaaaaaabaaaaaaaaaaaaaaaauaaaaqaaaaaaaaaaaaaaagaaaaeaaaaaaaaaabaaaabqaaabaaaaaaaaaaaqaaaayaaaaiaaaaaaaaaagaaaaaaaaa --mojo-platform-channel-handle=1560 /prefetch:2
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=utility --utility-sub-type=network.mojom.networkservice --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=cookieswithoutsamesitemustbesecure,samesitebydefaultcookies,sparerendererforsiteperprocess --lang=en-gb --service-sandbox-type=none --mojo-platform-channel-handle=2436 /prefetch:8
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=cookieswithoutsamesitemustbesecure,samesitebydefaultcookies,sparerendererforsiteperprocess --lang=en-gb --app-path="c:\program files (x86)\neatreader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2536 /prefetch:1
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=cookieswithoutsamesitemustbesecure,samesitebydefaultcookies,sparerendererforsiteperprocess --disable-gpu-compositing --lang=en-gb --app-path="c:\program files (x86)\neatreader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3064 /prefetch:1
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=crashpad-handler --user-data-dir=c:\users\user\appdata\roaming\neatreader /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler --database=c:\users\user\appdata\roaming\neatreader\crashpad --url=http://localhost:9000 "--annotation=_companyname=gauzy tech" "--annotation=_productname=neatreader desk app" --annotation=_version=8.1.4 --annotation=prod=electron --annotation=ver=13.0.1 --initial-client-data=0x47c,0x480,0x484,0x474,0x488,0x6df17c0,0x6df17d0,0x6df17dc Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=gpu-process --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=cookieswithoutsamesitemustbesecure,samesitebydefaultcookies,sparerendererforsiteperprocess --gpu-preferences=saaaaaaaaadgaaawaaaaaaaaaaaaaaaaaabgaaaaaaaoaaaaaaaaaaaaaaaaaaaaaaaaaaaaaab4aaaaaaaaahgaaaaaaaaakaaaaaqaaaagaaaaaaaaacgaaaaaaaaamaaaaaaaaaa4aaaaaaaaabaaaaaaaaaaaaaaaauaaaaqaaaaaaaaaaaaaaagaaaaeaaaaaaaaaabaaaabqaaabaaaaaaaaaaaqaaaayaaaaiaaaaaaaaaagaaaaaaaaa --mojo-platform-channel-handle=1560 /prefetch:2 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=utility --utility-sub-type=network.mojom.networkservice --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=cookieswithoutsamesitemustbesecure,samesitebydefaultcookies,sparerendererforsiteperprocess --lang=en-gb --service-sandbox-type=none --mojo-platform-channel-handle=2436 /prefetch:8 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=cookieswithoutsamesitemustbesecure,samesitebydefaultcookies,sparerendererforsiteperprocess --lang=en-gb --app-path="c:\program files (x86)\neatreader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2536 /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Process created: C:\Program Files (x86)\NeatReader\NeatReader.exe "c:\program files (x86)\neatreader\neatreader.exe" --type=renderer --field-trial-handle=1552,1988588544556221443,12342627507894332772,131072 --disable-features=cookieswithoutsamesitemustbesecure,samesitebydefaultcookies,sparerendererforsiteperprocess --disable-gpu-compositing --lang=en-gb --app-path="c:\program files (x86)\neatreader\resources\app.asar" --no-sandbox --no-zygote --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3064 /prefetch:1 Jump to behavior
Source: NeatReader Setup 8.1.4.exe, 00000000.00000003.1779564390.0000000006D57000.00000004.00001000.00020000.00000000.sdmp, NeatReader.exe, 00000001.00000000.1837107732.00000000062C3000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: ../../third_party/webrtc/modules/desktop_capture/win/window_capture_utils.ccFail to create instance of VirtualDesktopManagerChrome_WidgetWin_Progmanffff:%hx%n%4hx%n.
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86) VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader\resources VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader\resources\app.asar VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list\package.json VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list\index.js VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list\libs\darwin\index.js VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader\resources\app.asar.unpacked\node_modules\font-list\libs\win32\index.js VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader\resources VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Users\user\AppData\Roaming\NeatReader VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Users\user\AppData\Roaming\NeatReader\appData VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86) VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\NeatReader\NeatReader.exe Queries volume information: C:\Program Files (x86)\NeatReader\resources VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\NeatReader Setup 8.1.4.exe Code function: 0_2_0040338F EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,ExitProcess,CoUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_0040338F
No contacted IP infos