Windows Analysis Report
msgtopstdemo.exe

Overview

General Information

Sample name: msgtopstdemo.exe
Analysis ID: 1525130
MD5: fa7fccb539f58ea32e2a92a0a32af286
SHA1: 1ba6a04fe2d9ebf47d97f2c6b295c33ad5803a3e
SHA256: ee8fc4c0c9cb55699ef0bf026d5af42e7bb82d535ac8d84c8480569040f27257
Infos:

Detection

Score: 5
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to call native functions
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query locales information (e.g. system language)
Contains functionality to shutdown / reboot the system
Detected potential crypto function
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found potential string decryption / allocating functions
PE file contains executable resources (Code or Archives)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Source: msgtopstdemo.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.SOFTWARE LICENSE AGREEMENT This Software License Agreement is a legal agreement between you (an individual) and the www.datavare.com software product identified above which includes computer software and may include associated media printed materials or electronic documentation ("SOFTWARE PRODUCT"). With the instalment copying or using the Datavare Software and Services LLP PRODUCT indicates that you are agree to the terms of this AGREEMENT. In case you are not agree to the Agreement terms and conditions it is better to not to install or run the "www.datavare.com" SOFTWARE PRODUCTS; you may however return it to the right place (the seller) for getting a full refund.www.datavare.com PRODUCT LICENSE:The SOFTWARE PRODUCT is fully protected by copyright laws and international copyright treaties as well as other intellectual property laws and treaties. It is for licensed not for selling.Termination. Without prejudice to any other rights www.datavare.com may terminate this AGREEMENT if you fail to comply with the terms and conditions of this AGREEMENT. In such event you must destroy all copies of the SOFTWARE PRODUCT and all of its component parts.CHECK OUT OTHER RIGHTS AND LIMITATIONSClients cannot Resale Software. You might not resell or otherwise transfer for value the SOFTWARE PRODUCT.LICENSE - It is a Trial license that signifies you are permitted to use this trial version of "Datavare Software and Services LLP". Once the usage is over you can able to apply for getting the registration key that will eliminate the trial limitation and allow you to use a copy of "Datavare Software and Services LLP" on one computer. In case you wish to apply for multiple licenses it is must to get request for multiple registration keys where one for each user. www.datavare.com might also offer you with one key with multiple licenses.OWNERSHIP - This Software is copyrighted and owned by www.datavare.com. Your license confers no ownership or title in the Software. You can make a copy of this software solely for the purpose of back up. But License shall not modify copy duplicate reproduce license or sub license the Software or transfer or convey the Software or any right in the Software to anyone else without the prior written consent of Developer.LIMITED WARRANTY- www.datavare.com confirms that any type of implied warranty is concerned for only thirty (30) days. Warranty for the Software will perform substantially according to the user documentation for thirty (30) days from the day of receipt. CUSTOMER REMEDIES - In case the program fails to meet with www.datavare.com limited warranty a consumer can ask to refund the purchasing amount but it should be within 30 days of the shopping. This limited warranty is void if failure of the Software has resulted from abu
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.SOFTWARE LICENSE AGREEMENT This Software License Agreement is a legal agreement between you (an individual) and the www.datavare.com software product identified above which includes computer software and may include associated media printed materials or electronic documentation ("SOFTWARE PRODUCT"). With the instalment copying or using the Datavare Software and Services LLP PRODUCT indicates that you are agree to the terms of this AGREEMENT. In case you are not agree to the Agreement terms and conditions it is better to not to install or run the "www.datavare.com" SOFTWARE PRODUCTS; you may however return it to the right place (the seller) for getting a full refund.www.datavare.com PRODUCT LICENSE:The SOFTWARE PRODUCT is fully protected by copyright laws and international copyright treaties as well as other intellectual property laws and treaties. It is for licensed not for selling.Termination. Without prejudice to any other rights www.datavare.com may terminate this AGREEMENT if you fail to comply with the terms and conditions of this AGREEMENT. In such event you must destroy all copies of the SOFTWARE PRODUCT and all of its component parts.CHECK OUT OTHER RIGHTS AND LIMITATIONSClients cannot Resale Software. You might not resell or otherwise transfer for value the SOFTWARE PRODUCT.LICENSE - It is a Trial license that signifies you are permitted to use this trial version of "Datavare Software and Services LLP". Once the usage is over you can able to apply for getting the registration key that will eliminate the trial limitation and allow you to use a copy of "Datavare Software and Services LLP" on one computer. In case you wish to apply for multiple licenses it is must to get request for multiple registration keys where one for each user. www.datavare.com might also offer you with one key with multiple licenses.OWNERSHIP - This Software is copyrighted and owned by www.datavare.com. Your license confers no ownership or title in the Software. You can make a copy of this software solely for the purpose of back up. But License shall not modify copy duplicate reproduce license or sub license the Software or transfer or convey the Software or any right in the Software to anyone else without the prior written consent of Developer.LIMITED WARRANTY- www.datavare.com confirms that any type of implied warranty is concerned for only thirty (30) days. Warranty for the Software will perform substantially according to the user documentation for thirty (30) days from the day of receipt. CUSTOMER REMEDIES - In case the program fails to meet with www.datavare.com limited warranty a consumer can ask to refund the purchasing amount but it should be within 30 days of the shopping. This limited warranty is void if failure of the Software has resulted from abu
Source: msgtopstdemo.exe Static PE information: certificate valid
Source: msgtopstdemo.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: _c:\Users\test\Desktop\datavare products\DEMO-Datavare-MsgToPst\MsgToPst\MsgToPst\obj\x86\Debug\MsgToPst.pdb source: msgtopstdemo.tmp, 00000001.00000003.2027572801.0000000004948000.00000004.00001000.00020000.00000000.sdmp, MsgToPst.exe, 00000005.00000000.2026456010.000000000076A000.00000002.00000001.01000000.0000000A.sdmp, is-4FDGP.tmp.1.dr, is-01BK0.tmp.1.dr
Source: Binary string: d:\Bjornar\SVN\istool\isxdl\trunk\source\Release\isxdl.pdb source: msgtopstdemo.tmp, 00000001.00000003.2027572801.0000000004987000.00000004.00001000.00020000.00000000.sdmp, isxdl.dll.1.dr
Source: Binary string: c:\Users\test\Desktop\datavare products\DEMO-Datavare-MsgToPst\MsgToPst\MsgToPst\obj\x86\Debug\MsgToPst.pdb source: msgtopstdemo.tmp, 00000001.00000003.2027572801.0000000004948000.00000004.00001000.00020000.00000000.sdmp, MsgToPst.exe, 00000005.00000000.2026456010.000000000076A000.00000002.00000001.01000000.0000000A.sdmp, is-4FDGP.tmp.1.dr, is-01BK0.tmp.1.dr
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00476120 FindFirstFileA,FindNextFileA,FindClose, 1_2_00476120
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004531A4 FindFirstFileA,GetLastError, 1_2_004531A4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004648D0 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_004648D0
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00464D4C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_00464D4C
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00463344 FindFirstFileA,FindNextFileA,FindClose, 1_2_00463344
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0049998C FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose, 1_2_0049998C
Source: msgtopstdemo.exe String found in binary or memory: http://certificates.godaddy.com/repository/0
Source: msgtopstdemo.exe String found in binary or memory: http://certificates.godaddy.com/repository/gdig2.crt0
Source: msgtopstdemo.exe String found in binary or memory: http://certificates.starfieldtech.com/repository/1604
Source: msgtopstdemo.exe String found in binary or memory: http://certs.godaddy.com/repository/1301
Source: msgtopstdemo.exe String found in binary or memory: http://crl.godaddy.com/gdig2s5-2.crl0
Source: msgtopstdemo.exe String found in binary or memory: http://crl.godaddy.com/gdroot-g2.crl0F
Source: msgtopstdemo.exe String found in binary or memory: http://crl.starfieldtech.com/repository/0
Source: msgtopstdemo.exe String found in binary or memory: http://crl.starfieldtech.com/repository/sfsroot.crl0P
Source: MsgToPst.exe, 00000005.00000002.2952651282.00000000012F0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ns.ado
Source: msgtopstdemo.exe String found in binary or memory: http://ocsp.godaddy.com/0
Source: msgtopstdemo.exe String found in binary or memory: http://ocsp.godaddy.com/05
Source: msgtopstdemo.exe String found in binary or memory: http://ocsp.starfieldtech.com/0D
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.carterandcone.coml
Source: msgtopstdemo.tmp, 00000001.00000003.1701151209.000000000215C000.00000004.00001000.00020000.00000000.sdmp, msgtopstdemo.tmp, 00000001.00000003.1701048720.0000000003130000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.datavare.com/
Source: msgtopstdemo.tmp, 00000001.00000003.2029636409.0000000002168000.00000004.00001000.00020000.00000000.sdmp, msgtopstdemo.tmp, 00000001.00000003.1701151209.000000000215C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.datavare.com/B
Source: msgtopstdemo.tmp, 00000001.00000003.2027572801.0000000004948000.00000004.00001000.00020000.00000000.sdmp, MsgToPst.exe, 00000005.00000000.2026456010.000000000076A000.00000002.00000001.01000000.0000000A.sdmp, is-4FDGP.tmp.1.dr, is-01BK0.tmp.1.dr String found in binary or memory: http://www.datavare.com/contact-us.html
Source: msgtopstdemo.tmp, 00000001.00000003.2027572801.0000000004948000.00000004.00001000.00020000.00000000.sdmp, MsgToPst.exe, 00000005.00000000.2026456010.000000000076A000.00000002.00000001.01000000.0000000A.sdmp, is-4FDGP.tmp.1.dr, is-01BK0.tmp.1.dr String found in binary or memory: http://www.datavare.com/software/order/msg-to-pst-expert.html
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/?
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers8
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers?
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designersG
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fonts.com
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn/bThe
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn/cThe
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.galapagosdesign.com/DPlease
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.goodfont.co.kr
Source: msgtopstdemo.tmp, msgtopstdemo.tmp, 00000001.00000000.1700355107.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-0L47Q.tmp.1.dr, msgtopstdemo.tmp.0.dr String found in binary or memory: http://www.innosetup.com/
Source: isxdl.dll.1.dr String found in binary or memory: http://www.istool.org/
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.jiyu-kobo.co.jp/
Source: msgtopstdemo.exe String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline
Source: msgtopstdemo.exe String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: msgtopstdemo.exe, 00000000.00000003.1699783757.0000000002370000.00000004.00001000.00020000.00000000.sdmp, msgtopstdemo.exe, 00000000.00000003.1699586406.0000000002470000.00000004.00001000.00020000.00000000.sdmp, msgtopstdemo.tmp, msgtopstdemo.tmp, 00000001.00000000.1700355107.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-0L47Q.tmp.1.dr, msgtopstdemo.tmp.0.dr String found in binary or memory: http://www.remobjects.com/ps
Source: msgtopstdemo.exe, 00000000.00000003.1699783757.0000000002370000.00000004.00001000.00020000.00000000.sdmp, msgtopstdemo.exe, 00000000.00000003.1699586406.0000000002470000.00000004.00001000.00020000.00000000.sdmp, msgtopstdemo.tmp, 00000001.00000000.1700355107.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-0L47Q.tmp.1.dr, msgtopstdemo.tmp.0.dr String found in binary or memory: http://www.remobjects.com/psU
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sajatypeworks.com
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sakkal.com
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sandoll.co.kr
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.tiro.com
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.typography.netD
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.urwpp.deDPlease
Source: MsgToPst.exe, 00000005.00000002.2954898074.0000000006D72000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.zhongyicts.com.cn
Source: msgtopstdemo.exe String found in binary or memory: https://certs.godaddy.com/repository/0
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00423FD4 NtdllDefWindowProc_A, 1_2_00423FD4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00412A28 NtdllDefWindowProc_A, 1_2_00412A28
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0042F9C0 NtdllDefWindowProc_A, 1_2_0042F9C0
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00479D08 NtdllDefWindowProc_A, 1_2_00479D08
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00457D90 PostMessageA,PostMessageA,SetForegroundWindow,NtdllDefWindowProc_A, 1_2_00457D90
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0042ED84: CreateFileA,DeviceIoControl,GetLastError,CloseHandle,SetLastError, 1_2_0042ED84
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_004098E8 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_004098E8
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00455D80 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 1_2_00455D80
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_00408888 0_2_00408888
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00468034 1_2_00468034
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00471688 1_2_00471688
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0048F6BC 1_2_0048F6BC
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00435768 1_2_00435768
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00488030 1_2_00488030
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0046A088 1_2_0046A088
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00452100 1_2_00452100
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0043E1F0 1_2_0043E1F0
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004307FC 1_2_004307FC
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00444968 1_2_00444968
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00434A64 1_2_00434A64
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00444F10 1_2_00444F10
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00488F90 1_2_00488F90
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00431388 1_2_00431388
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00445608 1_2_00445608
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0045F8C0 1_2_0045F8C0
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0045B970 1_2_0045B970
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00445A14 1_2_00445A14
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Code function: 5_2_00DCDCF4 5_2_00DCDCF4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 00446274 appears 45 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 0040596C appears 114 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 00453AAC appears 97 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 0043497C appears 32 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 00458718 appears 79 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 00403400 appears 62 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 0040905C appears 45 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 00407D44 appears 43 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 00446544 appears 58 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 0045850C appears 100 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 00403494 appears 84 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 0040357C appears 33 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 00406F14 appears 45 times
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: String function: 00403684 appears 229 times
Source: msgtopstdemo.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: msgtopstdemo.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: msgtopstdemo.tmp.0.dr Static PE information: Resource name: RT_VERSION type: 370 sysV pure executable not stripped
Source: is-0L47Q.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-0L47Q.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-0L47Q.tmp.1.dr Static PE information: Resource name: RT_VERSION type: 370 sysV pure executable not stripped
Source: msgtopstdemo.exe, 00000000.00000003.1699586406.000000000254A000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs msgtopstdemo.exe
Source: msgtopstdemo.exe, 00000000.00000003.1699783757.0000000002446000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs msgtopstdemo.exe
Source: msgtopstdemo.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engine Classification label: clean5.winEXE@5/14@0/0
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_004098E8 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_004098E8
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00455D80 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 1_2_00455D80
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004565A8 GetModuleHandleA,GetProcAddress,GetDiskFreeSpaceExA,GetDiskFreeSpaceA, 1_2_004565A8
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00456DD4 CoCreateInstance,CoCreateInstance,SysFreeString,SysFreeString, 1_2_00456DD4
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_0040A0D4 FindResourceA,SizeofResource,LoadResource,LockResource, 0_2_0040A0D4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Users\user\AppData\Local\Programs Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Mutant created: NULL
Source: C:\Users\user\Desktop\msgtopstdemo.exe File created: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File read: C:\Windows\win.ini Jump to behavior
Source: C:\Users\user\Desktop\msgtopstdemo.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: msgtopstdemo.exe String found in binary or memory: need to be updated. /RESTARTAPPLICATIONS Instructs Setup to restart applications. /NORESTARTAPPLICATIONS Prevents Setup from restarting applications. /LOADINF="filename" Instructs Setup to load the settings from the specified file after having checked t
Source: msgtopstdemo.exe String found in binary or memory: /LOADINF="filename"
Source: C:\Users\user\Desktop\msgtopstdemo.exe File read: C:\Users\user\Desktop\msgtopstdemo.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\msgtopstdemo.exe "C:\Users\user\Desktop\msgtopstdemo.exe"
Source: C:\Users\user\Desktop\msgtopstdemo.exe Process created: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp "C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp" /SL5="$20450,2062666,288768,C:\Users\user\Desktop\msgtopstdemo.exe"
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe "C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe"
Source: C:\Users\user\Desktop\msgtopstdemo.exe Process created: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp "C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp" /SL5="$20450,2062666,288768,C:\Users\user\Desktop\msgtopstdemo.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe "C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe" Jump to behavior
Source: C:\Users\user\Desktop\msgtopstdemo.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\msgtopstdemo.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32 Jump to behavior
Source: Datavare MSG to PST Converter - Demo Version.lnk.1.dr LNK file: ..\..\..\..\..\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Window found: window name: TSelectLanguageForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: OK
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Automated click: I accept the agreement
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.SOFTWARE LICENSE AGREEMENT This Software License Agreement is a legal agreement between you (an individual) and the www.datavare.com software product identified above which includes computer software and may include associated media printed materials or electronic documentation ("SOFTWARE PRODUCT"). With the instalment copying or using the Datavare Software and Services LLP PRODUCT indicates that you are agree to the terms of this AGREEMENT. In case you are not agree to the Agreement terms and conditions it is better to not to install or run the "www.datavare.com" SOFTWARE PRODUCTS; you may however return it to the right place (the seller) for getting a full refund.www.datavare.com PRODUCT LICENSE:The SOFTWARE PRODUCT is fully protected by copyright laws and international copyright treaties as well as other intellectual property laws and treaties. It is for licensed not for selling.Termination. Without prejudice to any other rights www.datavare.com may terminate this AGREEMENT if you fail to comply with the terms and conditions of this AGREEMENT. In such event you must destroy all copies of the SOFTWARE PRODUCT and all of its component parts.CHECK OUT OTHER RIGHTS AND LIMITATIONSClients cannot Resale Software. You might not resell or otherwise transfer for value the SOFTWARE PRODUCT.LICENSE - It is a Trial license that signifies you are permitted to use this trial version of "Datavare Software and Services LLP". Once the usage is over you can able to apply for getting the registration key that will eliminate the trial limitation and allow you to use a copy of "Datavare Software and Services LLP" on one computer. In case you wish to apply for multiple licenses it is must to get request for multiple registration keys where one for each user. www.datavare.com might also offer you with one key with multiple licenses.OWNERSHIP - This Software is copyrighted and owned by www.datavare.com. Your license confers no ownership or title in the Software. You can make a copy of this software solely for the purpose of back up. But License shall not modify copy duplicate reproduce license or sub license the Software or transfer or convey the Software or any right in the Software to anyone else without the prior written consent of Developer.LIMITED WARRANTY- www.datavare.com confirms that any type of implied warranty is concerned for only thirty (30) days. Warranty for the Software will perform substantially according to the user documentation for thirty (30) days from the day of receipt. CUSTOMER REMEDIES - In case the program fails to meet with www.datavare.com limited warranty a consumer can ask to refund the purchasing amount but it should be within 30 days of the shopping. This limited warranty is void if failure of the Software has resulted from abu
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.SOFTWARE LICENSE AGREEMENT This Software License Agreement is a legal agreement between you (an individual) and the www.datavare.com software product identified above which includes computer software and may include associated media printed materials or electronic documentation ("SOFTWARE PRODUCT"). With the instalment copying or using the Datavare Software and Services LLP PRODUCT indicates that you are agree to the terms of this AGREEMENT. In case you are not agree to the Agreement terms and conditions it is better to not to install or run the "www.datavare.com" SOFTWARE PRODUCTS; you may however return it to the right place (the seller) for getting a full refund.www.datavare.com PRODUCT LICENSE:The SOFTWARE PRODUCT is fully protected by copyright laws and international copyright treaties as well as other intellectual property laws and treaties. It is for licensed not for selling.Termination. Without prejudice to any other rights www.datavare.com may terminate this AGREEMENT if you fail to comply with the terms and conditions of this AGREEMENT. In such event you must destroy all copies of the SOFTWARE PRODUCT and all of its component parts.CHECK OUT OTHER RIGHTS AND LIMITATIONSClients cannot Resale Software. You might not resell or otherwise transfer for value the SOFTWARE PRODUCT.LICENSE - It is a Trial license that signifies you are permitted to use this trial version of "Datavare Software and Services LLP". Once the usage is over you can able to apply for getting the registration key that will eliminate the trial limitation and allow you to use a copy of "Datavare Software and Services LLP" on one computer. In case you wish to apply for multiple licenses it is must to get request for multiple registration keys where one for each user. www.datavare.com might also offer you with one key with multiple licenses.OWNERSHIP - This Software is copyrighted and owned by www.datavare.com. Your license confers no ownership or title in the Software. You can make a copy of this software solely for the purpose of back up. But License shall not modify copy duplicate reproduce license or sub license the Software or transfer or convey the Software or any right in the Software to anyone else without the prior written consent of Developer.LIMITED WARRANTY- www.datavare.com confirms that any type of implied warranty is concerned for only thirty (30) days. Warranty for the Software will perform substantially according to the user documentation for thirty (30) days from the day of receipt. CUSTOMER REMEDIES - In case the program fails to meet with www.datavare.com limited warranty a consumer can ask to refund the purchasing amount but it should be within 30 days of the shopping. This limited warranty is void if failure of the Software has resulted from abu
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: msgtopstdemo.exe Static PE information: certificate valid
Source: msgtopstdemo.exe Static file information: File size 2391528 > 1048576
Source: msgtopstdemo.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: _c:\Users\test\Desktop\datavare products\DEMO-Datavare-MsgToPst\MsgToPst\MsgToPst\obj\x86\Debug\MsgToPst.pdb source: msgtopstdemo.tmp, 00000001.00000003.2027572801.0000000004948000.00000004.00001000.00020000.00000000.sdmp, MsgToPst.exe, 00000005.00000000.2026456010.000000000076A000.00000002.00000001.01000000.0000000A.sdmp, is-4FDGP.tmp.1.dr, is-01BK0.tmp.1.dr
Source: Binary string: d:\Bjornar\SVN\istool\isxdl\trunk\source\Release\isxdl.pdb source: msgtopstdemo.tmp, 00000001.00000003.2027572801.0000000004987000.00000004.00001000.00020000.00000000.sdmp, isxdl.dll.1.dr
Source: Binary string: c:\Users\test\Desktop\datavare products\DEMO-Datavare-MsgToPst\MsgToPst\MsgToPst\obj\x86\Debug\MsgToPst.pdb source: msgtopstdemo.tmp, 00000001.00000003.2027572801.0000000004948000.00000004.00001000.00020000.00000000.sdmp, MsgToPst.exe, 00000005.00000000.2026456010.000000000076A000.00000002.00000001.01000000.0000000A.sdmp, is-4FDGP.tmp.1.dr, is-01BK0.tmp.1.dr
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004489CC LoadLibraryExA,LoadLibraryA,GetProcAddress, 1_2_004489CC
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_00406A18 push 00406A55h; ret 0_2_00406A4D
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_004040B5 push eax; ret 0_2_004040F1
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_00404185 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_00404206 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_004042E8 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_00404283 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_004093B4 push 004093E7h; ret 0_2_004093DF
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_00408580 push ecx; mov dword ptr [esp], eax 0_2_00408585
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00409D9C push 00409DD9h; ret 1_2_00409DD1
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0041A078 push ecx; mov dword ptr [esp], ecx 1_2_0041A07D
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00452100 push ecx; mov dword ptr [esp], eax 1_2_00452105
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0040A273 push ds; ret 1_2_0040A29D
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004062C4 push ecx; mov dword ptr [esp], eax 1_2_004062C5
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0040A29F push ds; ret 1_2_0040A2A0
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00460518 push ecx; mov dword ptr [esp], ecx 1_2_0046051C
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00496594 push ecx; mov dword ptr [esp], ecx 1_2_00496599
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004587B4 push 004587ECh; ret 1_2_004587E4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00410930 push ecx; mov dword ptr [esp], edx 1_2_00410935
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00486A94 push ecx; mov dword ptr [esp], ecx 1_2_00486A99
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00478D50 push ecx; mov dword ptr [esp], edx 1_2_00478D51
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00412D78 push 00412DDBh; ret 1_2_00412DD3
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0040D288 push ecx; mov dword ptr [esp], edx 1_2_0040D28A
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0040546D push eax; ret 1_2_004054A9
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0040553D push 00405749h; ret 1_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004055BE push 00405749h; ret 1_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0040563B push 00405749h; ret 1_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004056A0 push 00405749h; ret 1_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0040F7E8 push ecx; mov dword ptr [esp], edx 1_2_0040F7EA
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004438E0 push ecx; mov dword ptr [esp], ecx 1_2_004438E4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00459ACC push 00459B10h; ret 1_2_00459B08
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0049BD44 pushad ; retf 1_2_0049BD53
Source: C:\Users\user\Desktop\msgtopstdemo.exe File created: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Users\user\AppData\Local\Temp\is-0CF57.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Users\user\AppData\Local\Temp\is-0CF57.tmp\isxdl.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\Aspose.Email.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\is-4FDGP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\is-01BK0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\is-4AED4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\is-0L47Q.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Datavare MSG to PST Converter - Demo Version.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0042405C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, 1_2_0042405C
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0042405C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, 1_2_0042405C
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00422CAC SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, 1_2_00422CAC
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0041811E IsIconic,SetWindowPos, 1_2_0041811E
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00418120 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, 1_2_00418120
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004245E4 IsIconic,SetActiveWindow, 1_2_004245E4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0042462C IsIconic,SetActiveWindow,SetFocus, 1_2_0042462C
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004187D4 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, 1_2_004187D4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00484D28 IsIconic,GetWindowLongA,ShowWindow,ShowWindow, 1_2_00484D28
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0042F71C IsIconic,GetWindowLongA,GetWindowLongA,GetActiveWindow,MessageBoxA,SetActiveWindow,GetActiveWindow,MessageBoxA,SetActiveWindow, 1_2_0042F71C
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004179E8 IsIconic,GetCapture, 1_2_004179E8
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0041F568 GetVersion,SetErrorMode,LoadLibraryA,SetErrorMode,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary, 1_2_0041F568
Source: C:\Users\user\Desktop\msgtopstdemo.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Memory allocated: DC0000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Memory allocated: 2B10000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Memory allocated: 4B10000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-0CF57.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-0CF57.tmp\isxdl.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\Aspose.Email.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\is-4AED4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\is-0L47Q.tmp Jump to dropped file
Source: C:\Users\user\Desktop\msgtopstdemo.exe Evasive API call chain: GetSystemTime,DecisionNodes
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00476120 FindFirstFileA,FindNextFileA,FindClose, 1_2_00476120
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004531A4 FindFirstFileA,GetLastError, 1_2_004531A4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004648D0 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_004648D0
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00464D4C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_00464D4C
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00463344 FindFirstFileA,FindNextFileA,FindClose, 1_2_00463344
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0049998C FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose, 1_2_0049998C
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_0040A018 GetSystemInfo,VirtualQuery,VirtualProtect,VirtualProtect,VirtualQuery, 0_2_0040A018
Source: msgtopstdemo.tmp, 00000001.00000002.2030670411.0000000000596000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_004489CC LoadLibraryExA,LoadLibraryA,GetProcAddress, 1_2_004489CC
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0047974C ShellExecuteEx,GetLastError,MsgWaitForMultipleObjects,GetExitCodeProcess,CloseHandle, 1_2_0047974C
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0042F254 InitializeSecurityDescriptor,SetSecurityDescriptorDacl,CreateMutexA, 1_2_0042F254
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_0042E4EC AllocateAndInitializeSid,GetVersion,GetModuleHandleA,GetProcAddress,CheckTokenMembership,GetCurrentThread,OpenThreadToken,GetLastError,GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetLastError,GetTokenInformation,EqualSid,CloseHandle,FreeSid, 1_2_0042E4EC
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: GetLocaleInfoA, 0_2_0040565C
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: GetLocaleInfoA, 0_2_004056A8
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: GetLocaleInfoA, 1_2_004089B8
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: GetLocaleInfoA, 1_2_00408A04
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\OFFSYMXL.TTF VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00458DC4 GetTickCount,QueryPerformanceCounter,GetSystemTimeAsFileTime,GetCurrentProcessId,CreateNamedPipeA,GetLastError,CreateFileA,SetNamedPipeHandleState,CreateProcessA,CloseHandle,CloseHandle, 1_2_00458DC4
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_004026C4 GetSystemTime, 0_2_004026C4
Source: C:\Users\user\AppData\Local\Temp\is-UN1KP.tmp\msgtopstdemo.tmp Code function: 1_2_00455D38 GetUserNameA, 1_2_00455D38
Source: C:\Users\user\Desktop\msgtopstdemo.exe Code function: 0_2_00404654 GetModuleHandleA,GetVersion,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,SetProcessDEPPolicy, 0_2_00404654
Source: C:\Program Files (x86)\Datavare MSG to PST Converter - Demo Version\MsgToPst.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
No contacted IP infos