Windows Analysis Report
IZArc_4.5.exe

Overview

General Information

Sample name: IZArc_4.5.exe
Analysis ID: 1524802
MD5: 6a3326cf6e377ffe29f946104514b9db
SHA1: 00a76e4983e1655389e70e148721c5e4bf86c3cc
SHA256: 557dc67478b7ab0fd71187de08b3e4164a6d9b8e7d432dbe06713e930df60fe0
Infos:

Detection

Score: 5
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Creates a process in suspended mode (likely to inject code)
Drops PE files
Found dropped PE file which has not been started or loaded
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Registers a DLL
Sigma detected: Classes Autorun Keys Modification
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

Source: IZArc_4.5.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: 15.164.165.52.in-addr.arpa
Source: global traffic DNS traffic detected: DNS query: www.izarc.org
Source: global traffic DNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52234
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52231
Source: unknown Network traffic detected: HTTP traffic on port 52237 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52237
Source: unknown Network traffic detected: HTTP traffic on port 52231 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52235
Source: unknown Network traffic detected: HTTP traffic on port 52234 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52235 -> 443
Source: IZArc_4.5.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engine Classification label: clean5.winEXE@23/159@3/43
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Users\user\AppData\Local\Programs
Source: C:\Users\user\Desktop\IZArc_4.5.exe File created: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp
Source: Yara match File source: C:\Program Files (x86)\IZArc\is-GD2P4.tmp, type: DROPPED
Source: Yara match File source: 0000000E.00000000.1509843590.0000000000AB1000.00000020.00000001.01000000.0000000B.sdmp, type: MEMORY
Source: C:\Windows\System32\regsvr32.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Windows\System32\regsvr32.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Program Files (x86)\IZArc\IZArc.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Program Files (x86)\IZArc\IZArc.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Program Files (x86)\IZArc\IZArc.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Program Files (x86)\IZArc\IZArc.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File read: C:\Windows\win.ini
Source: C:\Users\user\Desktop\IZArc_4.5.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
Source: C:\Users\user\Desktop\IZArc_4.5.exe File read: C:\Users\user\Desktop\IZArc_4.5.exe
Source: unknown Process created: C:\Users\user\Desktop\IZArc_4.5.exe "C:\Users\user\Desktop\IZArc_4.5.exe"
Source: C:\Users\user\Desktop\IZArc_4.5.exe Process created: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp "C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp" /SL5="$90280,5047654,194560,C:\Users\user\Desktop\IZArc_4.5.exe"
Source: C:\Users\user\Desktop\IZArc_4.5.exe Process created: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp "C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp" /SL5="$90280,5047654,194560,C:\Users\user\Desktop\IZArc_4.5.exe"
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Windows\System32\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\IZArc\IZArcCM64.dll"
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Program Files (x86)\IZArc\IZArc.exe "C:\Program Files (x86)\IZArc\IZArc.exe" -sa
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Windows\System32\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\IZArc\IZArcCM64.dll"
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Program Files (x86)\IZArc\IZArc.exe "C:\Program Files (x86)\IZArc\IZArc.exe" -sa
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.izarc.org/donate
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2000,i,11753767500346397328,11824077582812530869,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.izarc.org/donate
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2000,i,11753767500346397328,11824077582812530869,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Windows\SysWOW64\notepad.exe "Notepad" C:\Program Files (x86)\IZArc\WhatsNew.txt
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Windows\SysWOW64\notepad.exe "Notepad" C:\Program Files (x86)\IZArc\WhatsNew.txt
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: unknown Process created: C:\Program Files (x86)\IZArc\IZArc.exe "C:\Program Files (x86)\IZArc\IZArc.exe"
Source: C:\Users\user\Desktop\IZArc_4.5.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\IZArc_4.5.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: shfolder.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: rstrtmgr.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: riched20.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: usp10.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: msls31.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: explorerframe.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: propsys.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: linkinfo.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: ntshrui.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: cscapi.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: apphelp.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: aclayers.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc_os.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: msimg32.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: version.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\regsvr32.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: msimg32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: version.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: apr.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wsock32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: unrar.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: cabinet5.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: olepro32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: propsys.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: ntshrui.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: cscapi.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: tar32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: 7za.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: bga32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: ungca32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: yz1.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: textshaping.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: windowscodecs.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: thumbcache.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: ieframe.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: netapi32.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: wkscli.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: msiso.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: secur32.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: mlang.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: policymanager.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: msvcp110_win.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: onecorecommonproxystub.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: mrmcorer.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: wldp.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: textshaping.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: efswrt.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: wintypes.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: oleacc.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: textinputframework.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: urlmon.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: iertutil.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: srvcli.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: propsys.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: policymanager.dll
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: msimg32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: version.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: apr.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wsock32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: unrar.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: cabinet5.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: olepro32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: propsys.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: ntshrui.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: cscapi.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: tar32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: 7za.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: bga32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: ungca32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: yz1.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: textshaping.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: windowscodecs.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: thumbcache.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: dataexchange.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: d3d11.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: dcomp.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: twinapi.appcore.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: dui70.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: duser.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: edputil.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: explorerframe.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: policymanager.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: windows.ui.fileexplorer.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: oleacc.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: xmllite.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: structuredquery.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: atlthunk.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: windows.fileexplorer.common.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: windows.storage.search.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: ieframe.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: netapi32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wkscli.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: msiso.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: iconcodecservice.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: linkinfo.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: twinapi.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: actxprxy.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: networkexplorer.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: secur32.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: mlang.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: wininet.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\IZArc\IZArc.exe Section loaded: xmllite.dll
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Window found: window name: TMainForm
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\IZArc\IZArc.exe Window detected: Number of UI elements: 13
Source: IZArc_4.5.exe Static file information: File size 5460056 > 1048576
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Windows\System32\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\IZArc\IZArcCM64.dll"
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\SFXS\is-89GT3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-GD2P4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-5320F.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-RCQMA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_isdecmp.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-298O3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-2IJKA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-EL6HL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-FJT9H.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-1FA2S.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-F7RL9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\SFXS\is-COCN4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\SFXS\is-P6KVM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\SFXS\is-SHJIS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-DUQ4P.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_shfoldr.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-BULUJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-B448I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\is-5KKH7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\SFXS\is-GFOJB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\Desktop\IZArc_4.5.exe File created: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\SFXS\is-H091R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\Program Files (x86)\IZArc\SFXS\is-3U52R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc\IZArc.lnk
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc\IZArc Help.lnk
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc\What's New.lnk
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc\Uninstall IZArc.lnk
Source: C:\Program Files (x86)\IZArc\IZArc.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Program Files (x86)\IZArc\IZArc.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\Desktop\IZArc_4.5.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\System32\regsvr32.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\System32\regsvr32.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\System32\regsvr32.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\IZArc\IZArc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-P6KVM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-89GT3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-SHJIS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-DUQ4P.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_shfoldr.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-BULUJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-5KKH7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-B448I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-5320F.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-RCQMA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-GFOJB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_isdecmp.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-H091R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-298O3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-2IJKA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-EL6HL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-FJT9H.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-1FA2S.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-3U52R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-F7RL9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Dropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-COCN4.tmp Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
Source: C:\Windows\System32\regsvr32.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
Source: C:\Program Files (x86)\IZArc\IZArc.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
Source: C:\Program Files (x86)\IZArc\IZArc.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
Source: C:\Program Files (x86)\IZArc\IZArc.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
Source: C:\Program Files (x86)\IZArc\IZArc.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
Source: C:\Program Files (x86)\IZArc\IZArc.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Program Files (x86)\IZArc\IZArc.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process information queried: ProcessInformation
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.izarc.org/donate
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp Queries volume information: C:\ VolumeInformation
Source: C:\Windows\SysWOW64\notepad.exe Queries volume information: C:\Program Files (x86)\IZArc\WHATSNEW.TXT VolumeInformation
Source: C:\Program Files (x86)\IZArc\IZArc.exe Queries volume information: C:\ VolumeInformation
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs