Windows Analysis Report
LRF-Demonstration-Software-2.0.0.4.zip

Overview

General Information

Sample name: LRF-Demonstration-Software-2.0.0.4.zip
Analysis ID: 1523394
MD5: 5227c7472490433f23661011d1822fca
SHA1: 916a590cb230db87ee2158275267efe801033d20
SHA256: a798a77a7983a3962be5a295f0a5858a36872d1b684b3d13e3e69b1d8b0259b0
Infos:

Detection

Score: 7
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Signatures

Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains long sleeps (>= 3 min)
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Launches processes in debugging mode, may be used to hinder debugging
May infect USB drives
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Potentially Suspicious Rundll32 Activity
Stores files to the Windows start menu directory
Stores large binary data to the registry

Classification

Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\15ca9238891111f0 Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe File created: C:\Users\user\AppData\Local\Temp\VSDC16E.tmp\install.log Jump to behavior
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Interactions\Microsoft.Expression.Interactions.pdbD} source: Microsoft.Expression.Interactions.dll.11.dr, Microsoft.Expression.Interactions.dll0.11.dr, Microsoft.Expression.Interactions.dll.deploy
Source: Binary string: D:\code\GitHub\NAudio\NAudio\obj\Release\NAudio.pdb source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2452640322.00000000051BC000.00000002.00000001.01000000.0000000E.sdmp, NAudio.dll0.11.dr, NAudio.dll.11.dr, NAudio.dll.deploy
Source: Binary string: C:\Git\LRF_Tester\obj\Debug\LRF Demonstration Software.pdb8S+RS+ DS+_CorExeMainmscoree.dll source: LRF Demonstration Software.exe.11.dr, LRF Demonstration Software.exe0.11.dr, LRF Demonstration Software.exe.deploy
Source: Binary string: C:\Git\LRF_Tester\obj\Debug\LRF Demonstration Software.pdb source: LRF Demonstration Software.exe.11.dr, LRF Demonstration Software.exe0.11.dr, LRF Demonstration Software.exe.deploy
Source: Binary string: f:\dd\trinity\appnet\fx\office\nopia\utilities\word\objr\i386\Microsoft.Office.Tools.Word.v4.0.Utilities.pdb source: Microsoft.Office.Tools.Word.v4.0.Utilities.dll0.11.dr, Microsoft.Office.Tools.Word.v4.0.Utilities.dll.11.dr, Microsoft.Office.Tools.Word.v4.0.Utilities.dll.deploy
Source: Binary string: Q:\cmd\8\out\binaries\x86ret\bin\i386\Bootstrapper\Engine\setup.pdb@ source: setup.exe
Source: Binary string: f:\dd\trinity\appnet\fx\office\nopia\utilities\word\objr\i386\Microsoft.Office.Tools.Word.v4.0.Utilities.pdbh source: Microsoft.Office.Tools.Word.v4.0.Utilities.dll0.11.dr, Microsoft.Office.Tools.Word.v4.0.Utilities.dll.11.dr, Microsoft.Office.Tools.Word.v4.0.Utilities.dll.deploy
Source: Binary string: Q:\cmd\8\out\binaries\x86ret\bin\i386\Bootstrapper\Engine\setup.pdb source: setup.exe
Source: Binary string: D:\Dev\Math.NET\mathnet-numerics\src\Numerics\obj\Release\net461\MathNet.Numerics.pdbSHA256|& source: MathNet.Numerics.dll0.11.dr, MathNet.Numerics.dll.11.dr, MathNet.Numerics.dll.deploy
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Interactions\Microsoft.Expression.Interactions.pdb source: Microsoft.Expression.Interactions.dll.11.dr, Microsoft.Expression.Interactions.dll0.11.dr, Microsoft.Expression.Interactions.dll.deploy
Source: Binary string: D:\Dev\Math.NET\mathnet-numerics\src\Numerics\obj\Release\net461\MathNet.Numerics.pdb source: MathNet.Numerics.dll0.11.dr, MathNet.Numerics.dll.11.dr, MathNet.Numerics.dll.deploy
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\System.Windows.Interactivity\System.Windows.Interactivity.pdb source: System.Windows.Interactivity.dll0.11.dr, System.Windows.Interactivity.dll.deploy
Source: Binary string: c:\DotNetZip\Zip Reduced\obj\Release\Ionic.Zip.Reduced.pdb source: LRF Demonstration Software.exe, 0000000C.00000002.2476614120.000000000706C000.00000002.00000001.01000000.00000010.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy
Source: LRF-Demonstration-Software-2.0.0.4.zip Binary or memory string: 2.0.0.4/autorun.inf[autorun]
Source: LRF-Demonstration-Software-2.0.0.4.zip Binary or memory string: 2.0.0.4/autorun.inf[autorun]
Source: LRF-Demonstration-Software-2.0.0.4.zip Binary or memory string: 2.0.0.4/autorun.inf
Source: LRF-Demonstration-Software-2.0.0.4.zip Binary or memory string: P2.0.0.4/autorun.inf
Source: autorun.inf Binary or memory string: [autorun]
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\Local\Apps\2.0\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\Local\Apps\ Jump to behavior
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2311645811.0000020780428000.00000004.00000800.00020000.00000000.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2311645811.0000020780428000.00000004.00000800.00020000.00000000.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 0000000C.00000002.2437755770.0000000004486000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://davidowens.wordpress.com/2010/09/07/html-5-canvas-and-dashed-lines/
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://docs.oasis-open.org/opendocument/meta/rdfa#
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, Microsoft.Expression.Interactions.dll.11.dr, Microsoft.Expression.Interactions.dll0.11.dr, Microsoft.Expression.Interactions.dll.deploy String found in binary or memory: http://expression/microsoft.expression.interactions.dll
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, System.Windows.Interactivity.dll0.11.dr, System.Windows.Interactivity.dll.deploy String found in binary or memory: http://expression/system.windows.interactivity.dll0
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://fontfabrik.com
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2311645811.0000020780428000.00000004.00000800.00020000.00000000.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://ocsp.comodoca.com0
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://ocsp.thawte.com0
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://openoffice.org/2004/calc
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://openoffice.org/2004/office
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://openoffice.org/2004/writer
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://openoffice.org/2005/report
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.000000000351C000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2418656962.0000000002C39000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.carterandcone.coml
Source: TeeChart.Standard.WPF.dll.deploy String found in binary or memory: http://www.codeplex.com/DotNetZip.
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/?
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers8
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers?
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designersG
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fonts.com
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn/bThe
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn/cThe
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.galapagosdesign.com/DPlease
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.goodfont.co.kr
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.jiyu-kobo.co.jp/
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.0000000003470000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.newtone.co.jp
Source: LRF Demonstration Software.exe, 0000000C.00000002.2437755770.00000000044EC000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AAC000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2418656962.0000000002AAB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.newtone.co.jp/
Source: LRF Demonstration Software.exe, 0000000C.00000002.2437755770.0000000004475000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003B35000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.newtone.co.jp/store/home.asp
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.0000000003470000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.newtone.co.jp/store/home.aspK0
Source: LRF Demonstration Software.exe, 0000000C.00000002.2437755770.00000000044F4000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.newtone.co.jpK
Source: LRF Demonstration Software.exe, 0000000C.00000000.1393095221.0000000000BA2000.00000002.00000001.01000000.0000000C.sdmp, LRF Demonstration Software.exe.11.dr, LRF Demonstration Software.exe0.11.dr, LRF Demonstration Software.exe.deploy String found in binary or memory: http://www.noptel.fi
Source: LRF Demonstration Software.application String found in binary or memory: http://www.noptel.fi/
Source: dfsvc.exe, 0000000B.00000002.2322666794.00000207F1A13000.00000004.00000020.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2317823508.00000207EDAE2000.00000004.00000020.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2322192295.00000207EFD89000.00000004.00000020.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2322069955.00000207EFD73000.00000004.00000020.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2322148896.00000207EFD7F000.00000004.00000020.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2322596864.00000207F1A08000.00000004.00000020.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2320893040.00000207EFC58000.00000004.00000020.00020000.00000000.sdmp, LRF Demonstration Software.exe, 0000000C.00000002.2414167079.0000000001358000.00000004.00000020.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2414126645.0000000000977000.00000004.00000020.00020000.00000000.sdmp, lrfd..tion_0000000000000000_0002.0000_none_d4004f438420bf16.cdf-ms.11.dr String found in binary or memory: http://www.noptel.fi/%%%
Source: dfsvc.exe, 0000000B.00000002.2318288546.00000207EDB58000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.noptel.fi/00000
Source: setup.exe String found in binary or memory: http://www.noptel.fi/Begin
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sajatypeworks.com
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sakkal.com
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sandoll.co.kr
Source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, dfsvc.exe, 0000000B.00000002.2311645811.0000020780428000.00000004.00000800.00020000.00000000.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://www.steema.com
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 0000000C.00000002.2437755770.0000000004518000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000034D6000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003ADD000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003ACD000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.steema.com/buy
Source: LRF Demonstration Software.exe, 0000000C.00000002.2437755770.0000000004454000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 0000000C.00000002.2437755770.00000000044DC000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2418656962.0000000002A5C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.steema.com/demo.tee
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003ACB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.steema.com/demo.ten
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.0000000003470000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 0000000C.00000002.2437755770.0000000004473000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003B33000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.steema.com/teechartnet/test.txt
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.steema.com/test.txt
Source: LRF Demonstration Software.exe, 0000000C.00000002.2459912053.0000000006C15000.00000002.00000001.01000000.0000000F.sdmp, LRF Demonstration Software.exe, 0000000C.00000002.2476614120.0000000007149000.00000002.00000001.01000000.00000010.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: http://www.steema.comT
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB6000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.teechart.net/demo.ten
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 0000000C.00000002.2437755770.000000000448C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.teechart.net/support/index.php
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.tiro.com
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.typography.netD
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.urwpp.deDPlease
Source: dfsvc.exe, 0000000B.00000002.2322148896.00000207EFD7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.w3.op
Source: dfsvc.exe, 0000000B.00000002.2311645811.000002078001B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.xrml.org/schema/2001/11/xrml2core
Source: dfsvc.exe, 0000000B.00000002.2311645811.000002078001B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.xrml.org/schema/2001/11/xrml2coreE
Source: dfsvc.exe, 0000000B.00000002.2319237629.00000207EF212000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.zhongyicts.com.cn
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.steema.com/buy
Source: LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003ACD000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.steema.com/buy-https://www.steema.com/linkIn/tnetstd_startup
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 0000000C.00000002.2459912053.0000000006C26000.00000002.00000001.01000000.0000000F.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2438009501.0000000003AB6000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2480061317.00000000067C2000.00000002.00000001.01000000.00000010.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy, TeeChart.Standard.dll.deploy String found in binary or memory: https://www.steema.com/files/public/teechart/html5/latest/src
Source: LRF Demonstration Software.exe, 0000000C.00000002.2418554175.00000000032CB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.steema.com/linkIn/tnetstd_startup
Source: classification engine Classification label: clean7.winZIP@9/59@0/0
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Deployment Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Mutant created: NULL
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe File created: C:\Users\user\AppData\Local\Temp\VSDC16E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File read: C:\Users\desktop.ini
Source: C:\Windows\System32\rundll32.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe "C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe"
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe"
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe "C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe"
Source: unknown Process created: C:\Windows\System32\rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\dfshim.dll",ShOpenVerbApplication C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\LRF Demonstration Software.application
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe "C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe"
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe" Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe "C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe" Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe "C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe" Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: msi.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: dfshim.dll Jump to behavior
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: dfshim.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dfshim.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: msvcp140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: mscoree.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dfshim.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: cryptsp.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: rsaenh.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dwrite.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windowscodecs.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: msvcp140_clr0400.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: propsys.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: xmllite.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windows.fileexplorer.common.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: linkinfo.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dui70.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: duser.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: explorerframe.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: thumbcache.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dataexchange.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: d3d11.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dcomp.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dxgi.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: twinapi.appcore.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windows.ui.fileexplorer.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: oleacc.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: structuredquery.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: atlthunk.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windows.storage.search.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: samlib.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: twinapi.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: ntshrui.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: cscapi.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: networkexplorer.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: cldapi.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: fltlib.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: uiautomationcore.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: mrmcorer.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windows.staterepositorycore.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wkscli.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: provsvc.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: actxprxy.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: policymanager.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: msvcp110_win.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: drprov.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: winsta.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: ntlanman.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: davclnt.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: davhlpr.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: dlnashext.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: playtodevice.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: devdispitemprovider.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: mmdevapi.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: devobj.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wpdshext.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: portabledeviceapi.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: msasn1.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: audiodev.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wmvcore.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: wmasf.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: mfperfhelper.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: appxdeploymentclient.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: bcp47mrm.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windows.ui.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: windowmanagementapi.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: inputhost.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: appxdeploymentclient.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: appxdeploymentclient.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: appxdeploymentclient.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: appxdeploymentclient.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: mfsrcsnk.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: mfplat.dll
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Section loaded: rtworkq.dll
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Window detected: Number of UI elements: 15
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Window detected: Number of UI elements: 13
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\15ca9238891111f0 Jump to behavior
Source: LRF-Demonstration-Software-2.0.0.4.zip Static file information: File size 5558595 > 1048576
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Interactions\Microsoft.Expression.Interactions.pdbD} source: Microsoft.Expression.Interactions.dll.11.dr, Microsoft.Expression.Interactions.dll0.11.dr, Microsoft.Expression.Interactions.dll.deploy
Source: Binary string: D:\code\GitHub\NAudio\NAudio\obj\Release\NAudio.pdb source: dfsvc.exe, 0000000B.00000002.2311645811.0000020780348000.00000004.00000800.00020000.00000000.sdmp, LRF Demonstration Software.exe, 00000010.00000002.2452640322.00000000051BC000.00000002.00000001.01000000.0000000E.sdmp, NAudio.dll0.11.dr, NAudio.dll.11.dr, NAudio.dll.deploy
Source: Binary string: C:\Git\LRF_Tester\obj\Debug\LRF Demonstration Software.pdb8S+RS+ DS+_CorExeMainmscoree.dll source: LRF Demonstration Software.exe.11.dr, LRF Demonstration Software.exe0.11.dr, LRF Demonstration Software.exe.deploy
Source: Binary string: C:\Git\LRF_Tester\obj\Debug\LRF Demonstration Software.pdb source: LRF Demonstration Software.exe.11.dr, LRF Demonstration Software.exe0.11.dr, LRF Demonstration Software.exe.deploy
Source: Binary string: f:\dd\trinity\appnet\fx\office\nopia\utilities\word\objr\i386\Microsoft.Office.Tools.Word.v4.0.Utilities.pdb source: Microsoft.Office.Tools.Word.v4.0.Utilities.dll0.11.dr, Microsoft.Office.Tools.Word.v4.0.Utilities.dll.11.dr, Microsoft.Office.Tools.Word.v4.0.Utilities.dll.deploy
Source: Binary string: Q:\cmd\8\out\binaries\x86ret\bin\i386\Bootstrapper\Engine\setup.pdb@ source: setup.exe
Source: Binary string: f:\dd\trinity\appnet\fx\office\nopia\utilities\word\objr\i386\Microsoft.Office.Tools.Word.v4.0.Utilities.pdbh source: Microsoft.Office.Tools.Word.v4.0.Utilities.dll0.11.dr, Microsoft.Office.Tools.Word.v4.0.Utilities.dll.11.dr, Microsoft.Office.Tools.Word.v4.0.Utilities.dll.deploy
Source: Binary string: Q:\cmd\8\out\binaries\x86ret\bin\i386\Bootstrapper\Engine\setup.pdb source: setup.exe
Source: Binary string: D:\Dev\Math.NET\mathnet-numerics\src\Numerics\obj\Release\net461\MathNet.Numerics.pdbSHA256|& source: MathNet.Numerics.dll0.11.dr, MathNet.Numerics.dll.11.dr, MathNet.Numerics.dll.deploy
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Interactions\Microsoft.Expression.Interactions.pdb source: Microsoft.Expression.Interactions.dll.11.dr, Microsoft.Expression.Interactions.dll0.11.dr, Microsoft.Expression.Interactions.dll.deploy
Source: Binary string: D:\Dev\Math.NET\mathnet-numerics\src\Numerics\obj\Release\net461\MathNet.Numerics.pdb source: MathNet.Numerics.dll0.11.dr, MathNet.Numerics.dll.11.dr, MathNet.Numerics.dll.deploy
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\System.Windows.Interactivity\System.Windows.Interactivity.pdb source: System.Windows.Interactivity.dll0.11.dr, System.Windows.Interactivity.dll.deploy
Source: Binary string: c:\DotNetZip\Zip Reduced\obj\Release\Ionic.Zip.Reduced.pdb source: LRF Demonstration Software.exe, 0000000C.00000002.2476614120.000000000706C000.00000002.00000001.01000000.00000010.sdmp, TeeChart.Standard.WPF.dll0.11.dr, TeeChart.Standard.WPF.dll.11.dr, TeeChart.Standard.WPF.dll.deploy
Source: MathNet.Numerics.dll.11.dr Static PE information: 0x8687854D [Wed Jul 10 00:20:29 2041 UTC]
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\Microsoft.Office.Tools.Word.v4.0.Utilities.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\System.Windows.Interactivity.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\micr..ions_31bf3856ad364e35_0004.0005_none_29fb1b4caf46359f\Microsoft.Expression.Interactions.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\teec..dard_7d79220c74c907b6_0004.07e2_none_9b188e4dd326a5a9\TeeChart.Standard.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\MathNet.Numerics.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\micr..ties_b03f5f7f11d50a3a_000a.0000_none_26248fa63945e711\Microsoft.Office.Tools.Word.v4.0.Utilities.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\syst..vity_31bf3856ad364e35_0004.0005_none_1b13e2ad9f564705\System.Windows.Interactivity.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\NAudio.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\NAudio.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\LRF Demonstration Software.exe Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\teec...wpf_7d79220c74c907b6_0004.07e2_none_99dee6c148ef9332\TeeChart.Standard.WPF.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\MathNet.Numerics.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\Microsoft.Expression.Interactions.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.WPF.dll Jump to dropped file
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe File created: C:\Users\user\AppData\Local\Temp\VSDC16E.tmp\install.log Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Noptel Oy Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Noptel Oy\LRF Demonstration Software.appref-ms Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Noptel Oy\LRF Demonstration Software online support.url Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Key value created or modified: HKEY_CURRENT_USER_Classes\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\PackageMetadata\{2ec93463-b0c3-45e1-8364-327e96aea856}_{60051b8f-4f12-400a-8e50-dd05ebd438d1}\lrfd..tion_0000000000000000_0002.0000_a549107a3fb23252 {c989bb7a-8385-4715-98cf-a741a8edb823}!ApplicationTrust Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Memory allocated: 207EB8E0000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Memory allocated: 207ED3E0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Memory allocated: 30F0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Memory allocated: 3290000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Memory allocated: 5290000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Memory allocated: F70000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Memory allocated: 28D0000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Memory allocated: 48D0000 memory reserve | memory write watch
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 600000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599889 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599778 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599666 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599554 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599442 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599331 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599203 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599091 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598980 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598869 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598758 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598646 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598534 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598407 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598281 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598169 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598057 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597945 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597830 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597706 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597579 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597451 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597340 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597229 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597117 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597005 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596893 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596767 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596624 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596513 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596401 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596289 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596177 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596065 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595922 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595794 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595682 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595570 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595458 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595347 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595219 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595092 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 594980 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 594868 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 594757 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Window / User API: threadDelayed 9430 Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Window / User API: windowPlacementGot 915 Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Window / User API: windowPlacementGot 379
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\Microsoft.Office.Tools.Word.v4.0.Utilities.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\System.Windows.Interactivity.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\micr..ions_31bf3856ad364e35_0004.0005_none_29fb1b4caf46359f\Microsoft.Expression.Interactions.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\teec..dard_7d79220c74c907b6_0004.07e2_none_9b188e4dd326a5a9\TeeChart.Standard.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\MathNet.Numerics.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\micr..ties_b03f5f7f11d50a3a_000a.0000_none_26248fa63945e711\Microsoft.Office.Tools.Word.v4.0.Utilities.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\syst..vity_31bf3856ad364e35_0004.0005_none_1b13e2ad9f564705\System.Windows.Interactivity.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\NAudio.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\NAudio.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\teec...wpf_7d79220c74c907b6_0004.07e2_none_99dee6c148ef9332\TeeChart.Standard.WPF.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\MathNet.Numerics.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\Microsoft.Expression.Interactions.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.WPF.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -6456360425798339s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -600000s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -599889s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -599778s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -599666s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -599554s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -599442s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -599331s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -599203s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -599091s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -598980s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -598869s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -598758s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -598646s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -598534s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -598407s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -598281s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -598169s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -598057s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -597945s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -597830s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -597706s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -597579s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -597451s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -597340s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -597229s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -597117s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -597005s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -596893s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -596767s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -596624s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -596513s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -596401s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -596289s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -596177s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -596065s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -595922s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -595794s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -595682s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -595570s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -595458s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -595347s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -595219s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -595092s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -594980s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -594868s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe TID: 4580 Thread sleep time: -594757s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 600000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599889 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599778 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599666 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599554 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599442 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599331 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599203 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 599091 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598980 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598869 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598758 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598646 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598534 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598407 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598281 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598169 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 598057 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597945 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597830 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597706 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597579 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597451 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597340 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597229 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597117 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 597005 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596893 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596767 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596624 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596513 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596401 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596289 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596177 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 596065 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595922 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595794 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595682 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595570 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595458 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595347 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595219 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 595092 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 594980 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 594868 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Thread delayed: delay time: 594757 Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\Local\Apps\2.0\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\ Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe File opened: C:\Users\user\AppData\Local\Apps\ Jump to behavior
Source: LRF Demonstration Software.exe, 00000010.00000002.2500184204.00000000086ED000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: LRF Demonstration Software.exe, 00000010.00000002.2513408198.000000000DC04000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Users\user\Desktop\LRF-Demonstration-Software-2.0.0.4\2.0.0.4\setup.exe Process created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe" Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userbrii.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userbrili.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userbriz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userFR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userFI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userFB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userST.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userSTI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userSTB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\userSTBI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\flat_officeFontsPreview.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\OFFSYM.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\OFFSYMSL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\OFFSYMSB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\OFFSYMXL.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\OFFSYML.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\OFFSYMB.TTF VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.WPF.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\MathNet.Numerics.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\NAudio.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\System.Windows.Interactivity.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\Microsoft.Expression.Interactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\LRF Demonstration Software.exe VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\Microsoft.Office.Tools.Word.v4.0.Utilities.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\LRF Demonstration Software.exe VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.WPF.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\NAudio.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\System.Windows.Interactivity.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\LRF Demonstration Software.exe VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\LRF Demonstration Software.exe.config VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\noptel_logo_12d.ico VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.WPF.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\MathNet.Numerics.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\NAudio.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\System.Windows.Interactivity.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\TeeChart.Standard.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\Microsoft.Expression.Interactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\LRF Demonstration Software.exe VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Queries volume information: C:\Users\user\AppData\Local\Temp\Deployment\Z3AMQ27M.OL5\VJKVR2K8.GZT\Microsoft.Office.Tools.Word.v4.0.Utilities.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\NAudio.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\TeeChart.Standard.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\TeeChart.Standard.WPF.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\NAudio.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\TeeChart.Standard.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\TeeChart.Standard.WPF.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Apps\2.0\Q8RBY9WD.CWT\05N1XM83.TV3\lrfd..tion_0000000000000000_0002.0000_a6c481c8d3f3a109\LRF Demonstration Software.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
No contacted IP infos