Windows Analysis Report
pktbuilder_2.2.0.221_x64.exe

Overview

General Information

Sample name: pktbuilder_2.2.0.221_x64.exe
Analysis ID: 1525392
MD5: 395115bafe04900ceb9547e2e783a2f7
SHA1: 0065cff2542af622e3b80092f1f02a91e68163c9
SHA256: fcd897039058f68e7fab0c25aa2374807f60f8a23c24e9a9bf63b102ce0925e2
Infos:

Detection

Score: 26
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Signatures

Disables security and backup related services
Infects executable files (exe, dll, sys, html)
Installs new ROOT certificates
Binary contains a suspicious time stamp
Checks for available system drives (often done to infect USB drives)
Contains capabilities to detect virtual machines
Contains functionality for read data from the clipboard
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to communicate with device drivers
Contains functionality to create guard pages, often used to hinder reverse engineering and debugging
Contains functionality to dynamically determine API calls
Contains functionality to modify clipboard data
Contains functionality to read the clipboard data
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates files inside the driver directory
Creates files inside the system directory
Creates or modifies windows services
Deletes files inside the Windows folder
Detected potential crypto function
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops PE files to the windows directory (C:\Windows)
Drops certificate files (DER)
Drops files with a non-matching file extension (content does not match file extension)
Enables debug privileges
Enables security privileges
Found dropped PE file which has not been started or loaded
Found evaded block containing many API calls
Found evasive API chain (may stop execution after checking a module file name)
Found evasive API chain checking for process token information
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE / OLE file has an invalid certificate
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
PE file does not import any functions
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses net.exe to stop services
Uses the system / local time for branch decision (may execute only at specific dates)

Classification

Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01004F6B InitializeSecurityDescriptor,InitializeAcl,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,SetSecurityDescriptorDacl,GetCurrentDirectoryA,GetSystemDirectoryA,QueryDosDeviceA,_strlwr,strstr,strstr,strstr,GetDiskFreeSpaceA,CryptAcquireContextA,sprintf,CryptGenRandom,sprintf,sprintf,CryptReleaseContext,GetSystemTime,SystemTimeToFileTime,DialogBoxParamA,DosDateTimeToFileTime,LocalFileTimeToFileTime,SetFileTime,CloseHandle,SendDlgItemMessageA,MoveFileExA,strstr,_stricmp,SendDlgItemMessageA,GetLastError,CreateFileA,SetFilePointer,SetFilePointer,SetEndOfFile,SetFilePointer, 7_2_01004F6B
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_010045EB GetFileAttributesA,LoadLibraryA,GetProcAddress,DecryptFileA,GetLastError, 7_2_010045EB
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDA189E __EH_prolog3,CryptQueryObject,GetLastError,CertCloseStore,CryptMsgClose,GetLastError,CertFreeCertificateContext,CertCloseStore,CryptMsgClose, 8_2_6BDA189E
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD87EBB CryptDecodeObject,SetLastError, 8_2_6BD87EBB
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD87E4C CryptHashPublicKeyInfo,SetLastError, 8_2_6BD87E4C
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD87E7C CryptMsgGetParam,SetLastError, 8_2_6BD87E7C
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD87E3B CryptMsgGetAndVerifySigner, 8_2_6BD87E3B
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD87E2A CryptQueryObject, 8_2_6BD87E2A
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDA189E __EH_prolog3,CryptQueryObject,GetLastError,CertCloseStore,CryptMsgClose,GetLastError,CertFreeCertificateContext,CertCloseStore,CryptMsgClose, 11_2_6BDA189E
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD87EBB CryptDecodeObject,SetLastError, 11_2_6BD87EBB
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD87E4C CryptHashPublicKeyInfo,SetLastError, 11_2_6BD87E4C
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD87E7C CryptMsgGetParam,SetLastError, 11_2_6BD87E7C
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD87E3B CryptMsgGetAndVerifySigner, 11_2_6BD87E3B
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD87E2A CryptQueryObject, 11_2_6BD87E2A
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_00287C27 _memset,CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,ReadFile,CryptHashData,ReadFile,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,GetLastError,CryptDestroyHash,CryptReleaseContext, 13_2_00287C27
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_00268281 _memset,CryptCATAdminCalcHashFromFileHandle,GetLastError,GetLastError,CryptCATAdminCalcHashFromFileHandle,GetLastError,WinVerifyTrust,WinVerifyTrust,WinVerifyTrust, 13_2_00268281
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_00268558 CryptHashPublicKeyInfo,GetLastError, 13_2_00268558
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_002686D9 DecryptFileW, 13_2_002686D9
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BD8281 _memset,CryptCATAdminCalcHashFromFileHandle,GetLastError,GetLastError,CryptCATAdminCalcHashFromFileHandle,GetLastError,WinVerifyTrust,WinVerifyTrust,WinVerifyTrust, 22_2_00BD8281
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BF7C27 _memset,CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,ReadFile,CryptHashData,ReadFile,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,GetLastError,CryptDestroyHash,CryptReleaseContext, 22_2_00BF7C27
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BD8558 CryptHashPublicKeyInfo,GetLastError, 22_2_00BD8558
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BD86D9 DecryptFileW, 22_2_00BD86D9
Source: pktbuilder_2.2.0.221_x64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Colasoft Capsa End User License AgreementCopyright (c) Colasoft. All rights reserved.This License Agreement is a legal contract between you (either as an individual or as an entity) and Colasoft ("COLASOFT") for the Colasoft Capsa and related add-ons ("SOFTWARE PRODUCT"). Please carefully read the following terms and conditions before using the Software Product. Installation or use of the SOFTWARE PRODUCT indicates your acceptance of this License Agreement.COPYRIGHTThe SOFTWARE PRODUCT and Documentation are copyrighted by COLASOFT and are protected by international copyright laws. The SOFTWARE PRODUCT contains copyrighted software of COLASOFT. All rights reserved. You agree not to remove any trademarks or copyright notices from the SOFTWARE PRODUCT and Documentations.LICENSE TYPES1. Single Seat Perpetual LicenseA Single Seat Perpetual License grants you the right to install and use the SOFTWARE PRODUCT on one single computer and provide access for an unlimited number of individuals. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first computer you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.2. 5 Seat LicenseA 5 Seat License grants you the right to install and use the SOFTWARE PRODUCT on five computers and provide access for an unlimited number of individuals with one single license key. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first five computers you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.NOT-FOR-RESALE COPIESIf the SOFTWARE PRODUCT is marked as a Not-For-Resale (NFR) copy you may not sell or transfer the usage license of the SOFTWARE PRODUCT for any kind of payment. An NFR copy of the SOFTWARE PRODUCT may only be used for purposes of demonstrating the SOFTWARE PRODUCT. With an NFR version of the SOFTWARE PRODUCT you may not make or distribute additional copies.DEMO VERSIONIf the SOFTWARE PRODUCT is marked as a demonstration version for the final user (DEMO) you must buy a legal license and delete all copies of the demo version after expiring the time limit. The demo version may be distributed freely by any kind of MEDIA Internet server BBS etc. as long as no changes are made and package content is not changed. FREE EDITIONIf the SOFTWARE PRODUCT is marked as a free edition for the final user (FREE) it provided you without charge. You may not use the SOFTWARE PRODUCT in your workplace or for commercial purpose. LIMITATION ON USEYou may not: permit other individuals to use the SOFTWARE PRODUCT except under the terms listed above; modify translate reverse engineer decompile decrypt extract disassemble or create der
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Colasoft Capsa End User License AgreementCopyright (c) Colasoft. All rights reserved.This License Agreement is a legal contract between you (either as an individual or as an entity) and Colasoft ("COLASOFT") for the Colasoft Capsa and related add-ons ("SOFTWARE PRODUCT"). Please carefully read the following terms and conditions before using the Software Product. Installation or use of the SOFTWARE PRODUCT indicates your acceptance of this License Agreement.COPYRIGHTThe SOFTWARE PRODUCT and Documentation are copyrighted by COLASOFT and are protected by international copyright laws. The SOFTWARE PRODUCT contains copyrighted software of COLASOFT. All rights reserved. You agree not to remove any trademarks or copyright notices from the SOFTWARE PRODUCT and Documentations.LICENSE TYPES1. Single Seat Perpetual LicenseA Single Seat Perpetual License grants you the right to install and use the SOFTWARE PRODUCT on one single computer and provide access for an unlimited number of individuals. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first computer you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.2. 5 Seat LicenseA 5 Seat License grants you the right to install and use the SOFTWARE PRODUCT on five computers and provide access for an unlimited number of individuals with one single license key. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first five computers you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.NOT-FOR-RESALE COPIESIf the SOFTWARE PRODUCT is marked as a Not-For-Resale (NFR) copy you may not sell or transfer the usage license of the SOFTWARE PRODUCT for any kind of payment. An NFR copy of the SOFTWARE PRODUCT may only be used for purposes of demonstrating the SOFTWARE PRODUCT. With an NFR version of the SOFTWARE PRODUCT you may not make or distribute additional copies.DEMO VERSIONIf the SOFTWARE PRODUCT is marked as a demonstration version for the final user (DEMO) you must buy a legal license and delete all copies of the demo version after expiring the time limit. The demo version may be distributed freely by any kind of MEDIA Internet server BBS etc. as long as no changes are made and package content is not changed. FREE EDITIONIf the SOFTWARE PRODUCT is marked as a free edition for the final user (FREE) it provided you without charge. You may not use the SOFTWARE PRODUCT in your workplace or for commercial purpose. LIMITATION ON USEYou may not: permit other individuals to use the SOFTWARE PRODUCT except under the terms listed above; modify translate reverse engineer decompile decrypt extract disassemble or create der
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Colasoft Capsa End User License AgreementCopyright (c) Colasoft. All rights reserved.This License Agreement is a legal contract between you (either as an individual or as an entity) and Colasoft ("COLASOFT") for the Colasoft Capsa and related add-ons ("SOFTWARE PRODUCT"). Please carefully read the following terms and conditions before using the Software Product. Installation or use of the SOFTWARE PRODUCT indicates your acceptance of this License Agreement.COPYRIGHTThe SOFTWARE PRODUCT and Documentation are copyrighted by COLASOFT and are protected by international copyright laws. The SOFTWARE PRODUCT contains copyrighted software of COLASOFT. All rights reserved. You agree not to remove any trademarks or copyright notices from the SOFTWARE PRODUCT and Documentations.LICENSE TYPES1. Single Seat Perpetual LicenseA Single Seat Perpetual License grants you the right to install and use the SOFTWARE PRODUCT on one single computer and provide access for an unlimited number of individuals. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first computer you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.2. 5 Seat LicenseA 5 Seat License grants you the right to install and use the SOFTWARE PRODUCT on five computers and provide access for an unlimited number of individuals with one single license key. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first five computers you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.NOT-FOR-RESALE COPIESIf the SOFTWARE PRODUCT is marked as a Not-For-Resale (NFR) copy you may not sell or transfer the usage license of the SOFTWARE PRODUCT for any kind of payment. An NFR copy of the SOFTWARE PRODUCT may only be used for purposes of demonstrating the SOFTWARE PRODUCT. With an NFR version of the SOFTWARE PRODUCT you may not make or distribute additional copies.DEMO VERSIONIf the SOFTWARE PRODUCT is marked as a demonstration version for the final user (DEMO) you must buy a legal license and delete all copies of the demo version after expiring the time limit. The demo version may be distributed freely by any kind of MEDIA Internet server BBS etc. as long as no changes are made and package content is not changed. FREE EDITIONIf the SOFTWARE PRODUCT is marked as a free edition for the final user (FREE) it provided you without charge. You may not use the SOFTWARE PRODUCT in your workplace or for commercial purpose. LIMITATION ON USEYou may not: permit other individuals to use the SOFTWARE PRODUCT except under the terms listed above; modify translate reverse engineer decompile decrypt extract disassemble or create der
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\unins000.dat Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-SQVEQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-N8PT0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-O8KO8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-S9K5O.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-U4N3E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-FTAR3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-FPF1L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-83JJP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-J304I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-GTJ7O.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-0E13V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-GDME8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-DKOJV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-FU1BO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-PDAAT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-8EHFU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-9E0NC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-P0E3Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-OKV67.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-6237I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-D18OI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-3330M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-N579M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-TL9NT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-B9V58.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-4L076.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\data Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\data\is-M5RD2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-1UONN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\data\is-O7UF7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-9V2FV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-KK3C2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-D4FHM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-CRRC6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-MI97R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-S9K6E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-0UF4L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TKILU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3ASFI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UCDVV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J6G3A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ETNA6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IOIRR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UNQ0D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-44OKD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QV0AN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SRNLF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LE8JF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-49IIN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4SMT8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S7GP5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M4F8T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N41CV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S94BH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DP4NL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KL6KG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-85O5U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SN03C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SK0LO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6E8DV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-G3FKB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SSTME.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RIUC6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-86DH3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F2S2V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8PQQI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LUA7M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NCBTK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A53GH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AAD9D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8N991.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MUKN9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0UJFQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BVH0Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U7V4U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-USI5Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PBN7I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-95M2E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D8K45.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U05L0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6IDIF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7DEK3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-59R3F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TH5KJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-P0UVC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S4SVH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PJNJK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U0ROA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CPJGV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AI1IF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4A3PB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CV2NT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JR8U0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CU8UM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-35MDD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QO4F5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1N8H8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-52PPT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NI8SH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0BNTQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-63T9E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N62TT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R1T7F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CCV7J.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BS9PB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QQ98D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-25430.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MR5K8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PSU7M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LCLR6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EO2NS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-33TFI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RDEF8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PM3RV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RKP2Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VTU99.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-T77UP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FSEKH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IQ7KJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SD2L3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-L97OV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HKVIJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7OLHU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HV6AR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I8GKL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DNS7U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NIMJJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AI467.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OE0SH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EKKA9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O3H6B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IIK6V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PH8FB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7NFJD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7Q4AU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-E49GS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SVUVS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KFS11.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NPDM3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H2GBM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M2PKR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-T7RKU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HDFGJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1AC34.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DF191.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SSIKR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-15MN5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ITL6U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BL8B5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-B7LAH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O40QH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LENAT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PT0U0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N9M3N.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TH1VH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I5F6P.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MTIOA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-55JI6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I5AUQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2D8M9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-53H4P.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AT6BL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ENF56.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DRSP5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VJH28.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FUF9T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EVAJD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-81FJ6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BPV3D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QI5AL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2U7U6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CHEC4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4NLF0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UR3FM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7S6EA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1KDFM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5RHVQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AMMUN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IA00G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-GJ6DK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2PC4I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IED1G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QOF5G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BALPN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1DB01.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9A15R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6KL23.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UOPBM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JSR8U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PJATD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EOVF1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PIDVA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O45A2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NQBU1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D3EP1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MIDKB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A1324.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KAU1C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-30S0S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2HDEG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UAM3T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N3159.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HSUR9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SMRLH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-35TM5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OQ9BD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-77JH0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PITL7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-C7CJI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LACPI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5V0UQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NHDTA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NHVAV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-Q8HPG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UEULF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SLQ1H.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-12HV2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TVSOU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EKQPM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TG0PK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1OM6J.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HSU9L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BP048.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JQG1C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0C9CB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BQ11C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VCS1S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LH2OH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-10AF1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9SNPS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8U4JA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2GV2Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-92G1E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SKBGS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TEUDB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9HK7V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-L7UA9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A9985.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-732ON.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-B6OJP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6MT4B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7DG5E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DI5I5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AR7M0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LDDUC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7TVIG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PERAE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4L02A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SL1R2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-K54T2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BIV69.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8I1GI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VJFH8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LE9MT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A0OUE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1EASE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-B89BK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LQ1LO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-C92VM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O2O5M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-37J8U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M3OJC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O6GAP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9D0G3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F1ORV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-680DG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8TIKE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FGK3D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-583BE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IRV5T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1I05E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-50QBB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PUFI4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-45T2A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-L0PQG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I3FNL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UA3UO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H6ICG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KFH4C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QT3S4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6D6K3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J3LI6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U0E7S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ELNGG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IVJ8T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-C3955.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CRLTL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-V6QGG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4KH7S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-T89R4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KTFIH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-G29RS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5T9FR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EVSDS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QPB78.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-L2DMD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1OSJG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NFRR4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-227GH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VIN7R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-40OPJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IM74L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J7NN5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-21URT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-92FST.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-79FG6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2O9NR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PD22B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AMDC5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SA67F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AOC3B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JJ1EU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-V3CA4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ALAOA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-GUJUE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J1UPD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7VDDH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U7OKC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-Q531S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MCQTH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MTD15.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-22LHG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KVDQC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JQJR2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KNP3N.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R0V9B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D618N.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VU2LN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-18780.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SDPPO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1691K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-V6PL8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8SAKO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ABT4C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R7LDR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9R25E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LNA4L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4U3F1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NM1A5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HAQM1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9GM6I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-00N3F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A0O7A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VBKQO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LVUT5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J40FD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PUSA1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DDJBB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H59V6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KNK4K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-Q8CB3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SP83J.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AV8NE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SN0OR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2K9N7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U6I38.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HTE4K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H6T5R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UBUF5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0SRE1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S04PH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9JM9B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9337M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8BNBM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HL4SS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R0T54.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R559I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-GD080.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-01A9E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9PKUT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F7CHG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EVLIN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-07ADV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3I10F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IG1G9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BBPVH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8RAD5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D9INH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-P2JAK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9VH69.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7JKTR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OUNLS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O0TP9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KKU2L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-86GAN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U37H7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EHF91.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EH0KD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M4KIH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-P1I3B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FQEQK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BBJVA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F1182.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S3D9V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7222P.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9GCB4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2LJI1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6936S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N3JA9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M8L3I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6KSB7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R1VVP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-V9NDR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BUEOC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AOM2B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ULVUF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MTJU7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-18CTB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3TQQ6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2FTGL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OR507.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9EKA7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ASQ9G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KOV84.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0Q3CG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-COOQN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KFFQV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FL5QJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3SAFS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8KREJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-GJODE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AGQ1R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LGUB3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F789K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5R8JJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PEQRJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ISHIS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5JKJI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6O2K6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-E8B9K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LMBG0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8ESO4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6MCA0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MD0HL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OADV6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6A272.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RJ53O.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PKFTE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SGRH6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-769K5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1VS47.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4GSQP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-E9TAP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-11ON4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-13624.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-II6RB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4F94N.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0DKBO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-K6J88.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JANKV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8A7BN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KSUHP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-715LA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-E4H1A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LUP0I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OSKCU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QF6S3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FNQU7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ERTNV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-K4C4V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F6U3B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LIHDB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-00PQM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0GJ5L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RQ65O.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I0IKG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-56S5G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0LBUO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RL3I5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D5CTE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R1495.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VQC3V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-C9QB8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DMCLS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-P08AC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QFQD2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MP47P.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-T6AFJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LBR1U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NCCLQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A86IH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3HP0A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S0HSI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-045TV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LJ8A7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SSJ1Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A3AR0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H8K98.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LD81K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LG9HQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7PII1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-11EVD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JSHVF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VBHI3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1MAAD.tmp Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore SRInitDone
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Colasoft Packet Builder_is1 Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe File created: C:\Users\user\AppData\Local\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_20241003_234245280-MSI_vc_red.msi.txt Jump to behavior
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe File created: C:\Users\user\AppData\Local\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_20241003_234257425-MSI_vc_red.msi.txt
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Program Files\CapsaDrv\DrvInstall.log
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1033\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1041\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1042\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1028\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\2052\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1040\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1036\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1031\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\3082\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1049\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1033\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1041\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1042\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1028\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\2052\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1040\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1036\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1031\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\3082\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1049\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1028\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1029\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1031\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1036\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1040\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1041\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1042\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1045\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1046\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1049\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1055\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\2052\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\3082\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1028\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1029\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1031\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1036\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1040\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1041\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1042\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1045\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1046\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1049\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1055\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\2052\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\3082\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1028\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1029\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1031\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1036\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1040\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1041\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1042\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1045\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1046\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1049\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1055\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\2052\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\3082\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1028\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1029\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1031\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1036\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1040\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1041\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1042\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1045\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1046\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1049\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1055\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\2052\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\3082\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\license.rtf
Source: C:\Windows\System32\msiexec.exe File opened: c:\Windows\SysWOW64\msvcr100.dll
Source: pktbuilder_2.2.0.221_x64.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: \For Work\Source Code\CodeJock_XTP\Xtreme ToolkitPro v16.3.1\Workspace\Resource\ResourceEn\Release\vc140x64\CSXTPRes1631EnUs.pdb source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2939452166.000000000018C000.00000004.00000010.00020000.00000000.sdmp
Source: Binary string: sfxcab.pdb source: vcredist_x86.exe, vcredist_x86.exe, 00000007.00000000.2161836064.0000000001002000.00000020.00000001.01000000.00000009.sdmp, vcredist_x86.exe, 00000007.00000002.2281054939.0000000001002000.00000020.00000001.01000000.00000009.sdmp, vcredist_x64.exe, 0000000A.00000002.2402144549.0000000001002000.00000020.00000001.01000000.00000010.sdmp, vcredist_x64.exe, 0000000A.00000000.2281999628.0000000001002000.00000020.00000001.01000000.00000010.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSMFCEX.pdb66 GCTL source: pktbuilder.exe, 00000018.00000002.2731507197.00007FFE115F7000.00000002.00000001.01000000.0000001D.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSMFCEX.pdb source: pktbuilder.exe, 00000018.00000002.2731507197.00007FFE115F7000.00000002.00000001.01000000.0000001D.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSPCE.pdb--$GCTL source: pktbuilder.exe, 00000018.00000002.2730614552.00007FFE1025D000.00000002.00000001.01000000.0000001F.sdmp
Source: Binary string: D:\projects\capsa\output\x64_Release\pdb\csupd.pdb;;+GCTL source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\WixDepCA.pdb source: vcredist2015_x86.exe, 0000000D.00000003.2553454307.00000000012C1000.00000004.00000020.00020000.00000000.sdmp, vcredist2015_x86.exe, 0000000D.00000003.2550740989.0000000001285000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\burn.pdb`E source: vcredist2015_x86.exe, 0000000D.00000003.2542003899.0000000001266000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: patchhooks.pdb source: Setup.exe, 0000000B.00000003.2337000688.0000000000EA0000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2336872678.0000000000E91000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\projects\capsa\output\x64_Release\pdb\csupd.pdb source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: D:\projects\capsa\output\x64_release\pdb\PktBuilder_Free.pdb source: pktbuilder.exe, 00000018.00000002.2722918282.00007FF6F2E81000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSDOM.pdb source: pktbuilder.exe, 00000018.00000002.2727490152.00007FFE0C0B5000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSUPDATE.pdb::"GCTL source: pktbuilder.exe, 00000018.00000002.2727849048.00007FFE0CFA3000.00000002.00000001.01000000.00000026.sdmp
Source: Binary string: Setup.pdb source: Setup.exe, Setup.exe, 0000000B.00000002.2398101425.00000000004F1000.00000020.00000001.01000000.00000011.sdmp, Setup.exe, 0000000B.00000000.2305441126.00000000004F1000.00000020.00000001.01000000.00000011.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\burn.pdb` source: vcredist2015_x64.exe, 00000016.00000000.2613910378.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000016.00000002.2634548426.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000017.00000000.2616534305.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000017.00000002.2642599043.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: D:\projects\capsa\output\x64_release\pdb\PktBuilder_Free.pdbTT, source: pktbuilder.exe, 00000018.00000002.2722918282.00007FF6F2E81000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSDOM.pdb!! source: pktbuilder.exe, 00000018.00000002.2727490152.00007FFE0C0B5000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSUPDATE.pdb source: pktbuilder.exe, 00000018.00000002.2727849048.00007FFE0CFA3000.00000002.00000001.01000000.00000026.sdmp
Source: Binary string: sqmapi.pdb source: Setup.exe, Setup.exe, 0000000B.00000002.2400635663.000000006F861000.00000020.00000001.01000000.00000013.sdmp
Source: Binary string: SetupEngine.pdb source: Setup.exe, Setup.exe, 0000000B.00000002.2400246217.000000006BD41000.00000020.00000001.01000000.00000012.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSPCE.pdb source: pktbuilder.exe, 00000018.00000002.2730614552.00007FFE1025D000.00000002.00000001.01000000.0000001F.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\burn.pdb`* source: vcredist2015_x86.exe, 0000000D.00000000.2403274922.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000D.00000002.2607207772.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000E.00000002.2611419868.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000E.00000000.2404949754.000000000028B000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\burn.pdb source: vcredist2015_x86.exe, 0000000D.00000000.2403274922.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000D.00000003.2542003899.0000000001266000.00000004.00000020.00020000.00000000.sdmp, vcredist2015_x86.exe, 0000000D.00000002.2607207772.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000E.00000002.2611419868.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000E.00000000.2404949754.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x64.exe, 00000016.00000000.2613910378.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000016.00000002.2634548426.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000017.00000000.2616534305.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000017.00000002.2642599043.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSPFE.pdb!! source: pktbuilder.exe, 00000018.00000002.2730254550.00007FFE1023A000.00000002.00000001.01000000.00000021.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSPFE.pdb source: pktbuilder.exe, 00000018.00000002.2730254550.00007FFE1023A000.00000002.00000001.01000000.00000021.sdmp

Spreading

barindex
Source: C:\Windows\System32\msiexec.exe System file written: C:\Windows\System32\msvcp100.dll
Source: C:\Windows\System32\msiexec.exe File opened: z:
Source: C:\Windows\System32\msiexec.exe File opened: x:
Source: C:\Windows\System32\msiexec.exe File opened: v:
Source: C:\Windows\System32\msiexec.exe File opened: t:
Source: C:\Windows\System32\msiexec.exe File opened: r:
Source: C:\Windows\System32\msiexec.exe File opened: p:
Source: C:\Windows\System32\msiexec.exe File opened: n:
Source: C:\Windows\System32\msiexec.exe File opened: l:
Source: C:\Windows\System32\msiexec.exe File opened: j:
Source: C:\Windows\System32\msiexec.exe File opened: h:
Source: C:\Windows\System32\msiexec.exe File opened: f:
Source: C:\Windows\System32\msiexec.exe File opened: b:
Source: C:\Windows\System32\msiexec.exe File opened: y:
Source: C:\Windows\System32\msiexec.exe File opened: w:
Source: C:\Windows\System32\msiexec.exe File opened: u:
Source: C:\Windows\System32\msiexec.exe File opened: s:
Source: C:\Windows\System32\msiexec.exe File opened: q:
Source: C:\Windows\System32\msiexec.exe File opened: o:
Source: C:\Windows\System32\msiexec.exe File opened: m:
Source: C:\Windows\System32\msiexec.exe File opened: k:
Source: C:\Windows\System32\msiexec.exe File opened: i:
Source: C:\Windows\System32\msiexec.exe File opened: g:
Source: C:\Windows\System32\msiexec.exe File opened: e:
Source: C:\Windows\System32\msiexec.exe File opened: c:
Source: C:\Windows\System32\msiexec.exe File opened: a:
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_010046B9 SendDlgItemMessageA,strstr,SetFileAttributesA,GetLastError,CopyFileA,SendDlgItemMessageA,strstr,SetFileAttributesA,CopyFileA,GetLastError,CopyFileA,SetFileAttributesA,SendDlgItemMessageA,_strlwr,GetLastError,MoveFileA,MoveFileA,_strlwr,strstr,FindFirstFileA,strrchr,SendDlgItemMessageA,DeleteFileA,Sleep,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,strchr,strrchr,SendDlgItemMessageA, 7_2_010046B9
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD75BC0 __EH_prolog3_GS,_memset,FindFirstFileW,FindNextFileW,FindClose, 8_2_6BD75BC0
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD74120 FindFirstFileW,GetFullPathNameW,SetLastError,_wcsrchr,_wcsrchr, 8_2_6BD74120
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F844281 memset,EnterCriticalSection,FindFirstFileW,LeaveCriticalSection,ctype,FindNextFileW,FindClose,ResetEvent,CreateThread,CloseHandle,GetLastError, 8_2_6F844281
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F858097 memset,memset,FindFirstFileW,DeleteFileW,GetLastError,FindNextFileW,FindClose, 8_2_6F858097
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD75BC0 __EH_prolog3_GS,_memset,FindFirstFileW,FindNextFileW,FindClose, 11_2_6BD75BC0
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD74120 FindFirstFileW,GetFullPathNameW,SetLastError,_wcsrchr,_wcsrchr, 11_2_6BD74120
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F864281 memset,EnterCriticalSection,FindFirstFileW,LeaveCriticalSection,ctype,FindNextFileW,FindClose,ResetEvent,CreateThread,CloseHandle,GetLastError, 11_2_6F864281
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F878097 memset,memset,FindFirstFileW,DeleteFileW,GetLastError,FindNextFileW,FindClose, 11_2_6F878097
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_00286D15 _memset,_memset,GetFileAttributesW,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,GetLastError,GetLastError,GetLastError,FindClose, 13_2_00286D15
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_00285D81 _memset,FindFirstFileW,FindClose, 13_2_00285D81
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_00268E6E _memset,FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 13_2_00268E6E
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BF6D15 _memset,_memset,GetFileAttributesW,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,GetLastError,GetLastError,GetLastError,FindClose, 22_2_00BF6D15
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BF5D81 _memset,FindFirstFileW,FindClose, 22_2_00BF5D81
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BD8E6E _memset,FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 22_2_00BD8E6E
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\NULL
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\NULL
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\NULL
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 4x nop then mov edx, dword ptr [esp+08h] 8_2_6F85DFB0
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 4x nop then mov edx, dword ptr [esp+08h] 8_2_6F85DF48
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 4x nop then mov edi, edi 8_2_6F859F68
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 4x nop then mov edi, edi 8_2_6F844BEC
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 4x nop then mov edx, dword ptr [esp+08h] 11_2_6F87DFB0
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 4x nop then mov edx, dword ptr [esp+08h] 11_2_6F87DF48
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 4x nop then mov edi, edi 11_2_6F879F68
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 4x nop then mov edi, edi 11_2_6F864BEC
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDB4EB6 URLDownloadToFileW, 8_2_6BDB4EB6
Source: pktbuilder.exe, 00000018.00000003.2673251463.0000021528691000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: 'host''www.linuxcommand.org''host''www.linuxcommand.org''host''www.littlefighter.com''host''www.live365.com''host''www.livejournal.com''host''www.livelinktechnology.net''host''www.liveperson.com''host''www.live-station.org''host''www.logitech.com.cn''host''www.lokalisten.de''host''www.macrovision.com''host''www.magicjack.com''host''www.mail.com/int''host''www.manageengine.com''host''www.mcafee.com''host''www.mcafee.com''host''www.mcafee.com''host''www.me2day.net''host'jED equals www.lokalisten.de (Lokalisten)
Source: pktbuilder.exe, 00000018.00000003.2673251463.0000021528691000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: 'www.java.com''host''www.jmarshall.com''host''www.joltid.com''host''www.jubii.com''host''www.jumptuit.com''host''www.jungledisk.com''host''www.juniper.net''host''www.juniper.net''host''www.juniper.net''host''www.kachayu.com''host''www.kankan.com''host''www.kaseya.com''host''www.keek.com''host''www.kiwoom.com''host''www.kugou.com''host''www.labnol.org''host''www.lastpass.com''host''www.letv.com''host''www.limelight.com''host''www.linkedin.com''host''www.linkedin.com' equals www.linkedin.com (Linkedin)
Source: pktbuilder.exe, 00000018.00000003.2673251463.0000021528691000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: 'www.linkedin.com' equals www.linkedin.com (Linkedin)
Source: pktbuilder.exe, 00000018.00000003.2673251463.0000021528691000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: 'www.lokalisten.de' equals www.lokalisten.de (Lokalisten)
Source: pktbuilder.exe, 00000018.00000003.2674466410.00000215287C5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: www.linkedin.com equals www.linkedin.com (Linkedin)
Source: pktbuilder.exe, 00000018.00000003.2674466410.00000215287C5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: www.lokalisten.de equals www.lokalisten.de (Lokalisten)
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000025D9000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000025D9000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0
Source: Setup.exe, 0000000B.00000003.2397494438.0000000000E16000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2397706492.0000000000E43000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2397380139.0000000000E12000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2397603028.0000000000E30000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000002.2398712340.0000000000E56000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2397834486.0000000000E54000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://go.%
Source: Setup.exe, 00000008.00000003.2193040080.0000000003260000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000008.00000003.2197114847.0000000003220000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2313247946.0000000002C80000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2317985175.0000000002C00000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://go.microsoft.
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000025D9000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000025D9000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000025D9000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000025D9000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0?
Source: vcredist2015_x86.exe, 0000000E.00000003.2606589603.00000000030E0000.00000004.00000020.00020000.00000000.sdmp, vcredist2015_x86.exe, 0000000E.00000003.2603155842.00000000034BC000.00000004.00000800.00020000.00000000.sdmp, vcredist2015_x64.exe, 00000017.00000003.2636150844.0000000002CA0000.00000004.00000020.00020000.00000000.sdmp, vcredist2015_x64.exe, 00000017.00000003.2630601825.0000000002EBC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010
Source: vcredist2015_x64.exe, 00000017.00000003.2630601825.0000000002EBC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010(
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000025D9000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2951849081.0000000000CEC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.colasoft.com
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675056020.00000000024F0000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000003.1679214259.0000000003480000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.colasoft.com(support
Source: pktbuilder.exe String found in binary or memory: http://www.colasoft.com.cn/
Source: pktbuilder.exe String found in binary or memory: http://www.colasoft.com.cn/crash_report/?product=cspb
Source: pktbuilder.exe, 00000018.00000002.2722918282.00007FF6F2E81000.00000002.00000001.01000000.00000019.sdmp String found in binary or memory: http://www.colasoft.com.cn/crash_report/?product=cspb%smui
Source: pktbuilder.exe, 00000018.00000002.2731507197.00007FFE115F7000.00000002.00000001.01000000.0000001D.sdmp String found in binary or memory: http://www.colasoft.com.cn/openno
Source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000003.1679214259.0000000003480000.00000004.00001000.00020000.00000000.sdmp, pktbuilder.exe String found in binary or memory: http://www.colasoft.com/
Source: pktbuilder.exe, 00000018.00000002.2731507197.00007FFE115F7000.00000002.00000001.01000000.0000001D.sdmp String found in binary or memory: http://www.colasoft.com/Click
Source: pktbuilder.exe String found in binary or memory: http://www.colasoft.com/capsa/
Source: pktbuilder.exe, 00000018.00000002.2731507197.00007FFE115F7000.00000002.00000001.01000000.0000001D.sdmp String found in binary or memory: http://www.colasoft.com/capsa/Click
Source: pktbuilder.exe String found in binary or memory: http://www.colasoft.com/etherlook/
Source: pktbuilder.exe, 00000018.00000002.2731507197.00007FFE115F7000.00000002.00000001.01000000.0000001D.sdmp String found in binary or memory: http://www.colasoft.com/etherlook/Click
Source: pktbuilder.exe String found in binary or memory: http://www.colasoft.com/jp/
Source: pktbuilder.exe, 00000018.00000002.2722918282.00007FF6F2E81000.00000002.00000001.01000000.00000019.sdmp String found in binary or memory: http://www.colasoft.com/jp/S0S0
Source: pktbuilder.exe String found in binary or memory: http://www.colasoft.com/jp/products/capsa-enterprise.php
Source: pktbuilder.exe, 00000018.00000002.2722918282.00007FF6F2E81000.00000002.00000001.01000000.00000019.sdmp String found in binary or memory: http://www.colasoft.com/jp/products/capsa-enterprise.phpS0S0
Source: pktbuilder.exe, pktbuilder.exe, 00000018.00000002.2731507197.00007FFE115F7000.00000002.00000001.01000000.0000001D.sdmp String found in binary or memory: http://www.colasoft.com/msn_monitor/
Source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000003.1679214259.0000000003480000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2963866073.00000000038E0000.00000004.00000020.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2945714436.0000000000860000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.colasoft.com/packet_builder/
Source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2951849081.0000000000CD6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.colasoft.com/pf
Source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2945714436.0000000000860000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.colasoft.com/purchas
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000002.2945541806.000000000221A000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675056020.00000000024F0000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2951849081.0000000000C29000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000003.1679214259.0000000003480000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2963866073.00000000038E0000.00000004.00000020.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2945714436.0000000000860000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.colasoft.com/purchase/
Source: pktbuilder.exe String found in binary or memory: http://www.colasoft.com/purchase/corporations.php
Source: pktbuilder.exe, 00000018.00000002.2722918282.00007FF6F2E81000.00000002.00000001.01000000.00000019.sdmp String found in binary or memory: http://www.colasoft.com/purchase/corporations.phpwindow_widthwindow_height
Source: pktbuilder.exe, 00000018.00000002.2719886862.00000215231B6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.colasoft.com/redirect/?product=CSPB&act=product_home
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000002.2945541806.0000000002293000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.colasoft.com03)
Source: pktbuilder.exe, pktbuilder.exe, 00000018.00000002.2722918282.00007FF6F2E81000.00000002.00000001.01000000.00000019.sdmp String found in binary or memory: http://www.packetech.com/forumdisplay.php?22-Colasoft-Products-(Sponsor)
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000000.1674625389.0000000000401000.00000020.00000001.01000000.00000003.sdmp String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FE35000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000025D9000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.globalsign.com/repository/0
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FB50000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000024F0000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000000.1677888832.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: https://www.innosetup.com/
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FB50000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000024F0000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000000.1677888832.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: https://www.remobjects.com/ps
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E5C500 GetKeyState,RedrawWindow,MessageBeep,calloc,free,isxdigit,RedrawWindow,#8043,#6724,RedrawWindow,#8043,#6724,OpenClipboard,GetClientRect,ScreenToClient,PtInRect,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalSize,#265,memset,#266,RedrawWindow,GlobalUnlock,CloseClipboard, 24_2_00007FF6F2E5C500
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E5CB10 OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,GlobalAlloc,GlobalLock,#296,#2431,#2415,#1641,#1641,memmove,free,free,GlobalUnlock,#1033,GlobalAlloc,GlobalLock,isprint,GlobalUnlock,SetClipboardData,SetClipboardData,CloseClipboard, 24_2_00007FF6F2E5CB10
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E72EE0 OpenClipboard,EmptyClipboard,CloseClipboard,SendMessageW,SendMessageW,?_Xlength_error@std@@YAXPEBD@Z,?_Xlength_error@std@@YAXPEBD@Z,GlobalAlloc,GlobalLock,memmove,GlobalUnlock,SetClipboardData,CloseClipboard, 24_2_00007FF6F2E72EE0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E5C500 GetKeyState,RedrawWindow,MessageBeep,calloc,free,isxdigit,RedrawWindow,#8043,#6724,RedrawWindow,#8043,#6724,OpenClipboard,GetClientRect,ScreenToClient,PtInRect,IsClipboardFormatAvailable,GetClipboardData,GlobalLock,GlobalSize,#265,memset,#266,RedrawWindow,GlobalUnlock,CloseClipboard, 24_2_00007FF6F2E5C500
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E79A80 GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,GetAsyncKeyState,#11854, 24_2_00007FF6F2E79A80
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{fb1bf615-1342-3a4c-9a87-982272badb62}\capsadrv.cat (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Program Files\CapsaDrv\is-LMN0D.tmp Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Users\user\AppData\Local\Temp\{13d931c2-7f9b-1540-9f88-92c719c22a36}\SETD1CE.tmp Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Users\user\AppData\Local\Temp\{13d931c2-7f9b-1540-9f88-92c719c22a36}\capsadrv.cat (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Program Files\CapsaDrv\capsadrv.cat (copy) Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{fb1bf615-1342-3a4c-9a87-982272badb62}\SETD597.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01003972 OpenEventA,WaitForSingleObject,CloseHandle,Sleep,LoadLibraryA,GetProcAddress,WaitForSingleObject,GetLastError,InitiateSystemShutdownA,GetLastError,WaitForSingleObject,GetLastError,GetVersionExA,GetVersionExA,GetVersionExA,GetSystemDirectoryA,strchr,CreateFileA,FlushFileBuffers,CloseHandle,NtShutdownSystem,FreeLibrary, 7_2_01003972
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_0100358B NtOpenProcessToken,NtAdjustPrivilegesToken,NtClose,NtClose, 7_2_0100358B
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_010034F4 NtOpenProcessToken,NtAdjustPrivilegesToken,NtClose,NtClose, 7_2_010034F4
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01002B13: GetDriveTypeA,CreateFileA,DeviceIoControl,CloseHandle, 7_2_01002B13
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01003972 OpenEventA,WaitForSingleObject,CloseHandle,Sleep,LoadLibraryA,GetProcAddress,WaitForSingleObject,GetLastError,InitiateSystemShutdownA,GetLastError,WaitForSingleObject,GetLastError,GetVersionExA,GetVersionExA,GetVersionExA,GetSystemDirectoryA,strchr,CreateFileA,FlushFileBuffers,CloseHandle,NtShutdownSystem,FreeLibrary, 7_2_01003972
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD94B5B ExitWindowsEx, 8_2_6BD94B5B
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD94B5B ExitWindowsEx, 11_2_6BD94B5B
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Windows\system32\DRIVERS\SETEBCE.tmp
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6af7aa.msi
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6af7ab.msp
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\SourceHash{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIFC7D.tmp
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\atl100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100chs.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100cht.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100deu.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100enu.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100esn.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100fra.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100ita.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100jpn.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100kor.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100rus.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfc100u.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfcm100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\mfcm100u.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\SysWOW64\vcomp100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_atl100_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100chs_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100cht_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100deu_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100enu_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100esn_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100fra_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100ita_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100jpn_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100kor_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100rus_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100u_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100u_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcp100_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcr100_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_vcomp100_x86
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6af7ae.msi
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6af7ae.msi
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6af7af.msp
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6af7af.msp
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6b26c9.msi
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6b26ca.msp
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\SourceHash{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSI2B7C.tmp
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\atl100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100chs.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100cht.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100deu.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100enu.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100esn.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100fra.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100ita.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100jpn.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100kor.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100rus.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfc100u.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfcm100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\mfcm100u.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcp100_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\msvcp100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\msvcr100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\system32\vcomp100.dll
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_atl100_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100chs_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100cht_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100deu_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100enu_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100esn_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100fra_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100ita_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100jpn_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100kor_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100rus_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100u_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100u_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcr100_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_vcomp100_x64
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\CacheSize.txt
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6b26ce.msi
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6b26ce.msi
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6b26cf.msp
Source: C:\Windows\System32\msiexec.exe File created: c:\Windows\Installer\6b26cf.msp
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\6b7900.msi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\SourceHash{65AD78AD-D23D-3A1E-9305-3AE65CD522C2}
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSI7AD4.tmp
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\vcamp140.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\concrt140.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\msvcp140.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vccorlib140.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vcomp140.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vcruntime140.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\6b7903.msi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\6b7903.msi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\6b7904.msi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\SourceHash{1045AB6F-6151-3634-8C2C-EE308AA1A6A7}
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSI81AB.tmp
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140chs.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140cht.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140deu.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140enu.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140esn.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140fra.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140ita.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140jpn.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140kor.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140rus.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfc140.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfc140u.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfcm140.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfcm140u.dll
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\6b7907.msi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\6b7907.msi
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\CapsaDrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\CapsaDrv\is-T4O6N.tmp
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\CapsaDrv\is-RKF1F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\is-ILTFF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\is-7BQUN.tmp
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Windows\INF\oem4.PNF
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Windows\system32\DRIVERS\SETEBCE.tmp
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Windows\system32\DRIVERS\SETEBCE.tmp
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\FileRepository\capsadrv.inf_amd64_dec1bfdc282b6315
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\drvstore.tmp
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\inf\oem4.inf
Source: C:\Windows\System32\msiexec.exe File deleted: C:\Windows\Installer\6af7ae.msi
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01008906 7_2_01008906
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_0100911E 7_2_0100911E
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01009558 7_2_01009558
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01008286 7_2_01008286
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_0100859D 7_2_0100859D
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01008CC5 7_2_01008CC5
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDAE7C2 8_2_6BDAE7C2
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDCC9DE 8_2_6BDCC9DE
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDCAD3E 8_2_6BDCAD3E
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDCC38B 8_2_6BDCC38B
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDCA292 8_2_6BDCA292
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDCA7E8 8_2_6BDCA7E8
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD6F75A 8_2_6BD6F75A
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDCB41F 8_2_6BDCB41F
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F849A50 8_2_6F849A50
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F85D81C 8_2_6F85D81C
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F85D064 8_2_6F85D064
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDAE7C2 11_2_6BDAE7C2
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDCC9DE 11_2_6BDCC9DE
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDCAD3E 11_2_6BDCAD3E
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDCC38B 11_2_6BDCC38B
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDCA292 11_2_6BDCA292
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDCA7E8 11_2_6BDCA7E8
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD6F75A 11_2_6BD6F75A
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDCB41F 11_2_6BDCB41F
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F869A50 11_2_6F869A50
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F87D81C 11_2_6F87D81C
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F87D064 11_2_6F87D064
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E51550 24_2_00007FF6F2E51550
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E70530 24_2_00007FF6F2E70530
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E5C500 24_2_00007FF6F2E5C500
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E73200 24_2_00007FF6F2E73200
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E4F190 24_2_00007FF6F2E4F190
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E4C190 24_2_00007FF6F2E4C190
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E74180 24_2_00007FF6F2E74180
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E5E140 24_2_00007FF6F2E5E140
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E77330 24_2_00007FF6F2E77330
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E49320 24_2_00007FF6F2E49320
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E482D0 24_2_00007FF6F2E482D0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E6C7A0 24_2_00007FF6F2E6C7A0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E5D78A 24_2_00007FF6F2E5D78A
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E72760 24_2_00007FF6F2E72760
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E5D902 24_2_00007FF6F2E5D902
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E5D589 24_2_00007FF6F2E5D589
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E4D560 24_2_00007FF6F2E4D560
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E7D6D0 24_2_00007FF6F2E7D6D0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E68B70 24_2_00007FF6F2E68B70
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E75CF0 24_2_00007FF6F2E75CF0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E4ACE0 24_2_00007FF6F2E4ACE0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E79CA0 24_2_00007FF6F2E79CA0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E609F0 24_2_00007FF6F2E609F0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E57B10 24_2_00007FF6F2E57B10
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E67AE0 24_2_00007FF6F2E67AE0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E45A80 24_2_00007FF6F2E45A80
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E58F90 24_2_00007FF6F2E58F90
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E4D090 24_2_00007FF6F2E4D090
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E63040 24_2_00007FF6F2E63040
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E4AEB0 24_2_00007FF6F2E4AEB0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E4CEA0 24_2_00007FF6F2E4CEA0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE0175E350 24_2_00007FFE0175E350
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE016CDBB0 24_2_00007FFE016CDBB0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE01770BA0 24_2_00007FFE01770BA0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE016DBD49 24_2_00007FFE016DBD49
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE016DA62C 24_2_00007FFE016DA62C
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE016CDCF0 24_2_00007FFE016CDCF0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE01770EC0 24_2_00007FFE01770EC0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE016CDE40 24_2_00007FFE016CDE40
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE016CC720 24_2_00007FFE016CC720
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE02B29B42 24_2_00007FFE02B29B42
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE02B2B810 24_2_00007FFE02B2B810
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE02B2F4E0 24_2_00007FFE02B2F4E0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE02AF5C9F 24_2_00007FFE02AF5C9F
Source: C:\Windows\System32\svchost.exe Process token adjusted: Security
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: String function: 6BD980F9 appears 578 times
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: String function: 6BDB8EA6 appears 109 times
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: String function: 6BD63A0D appears 43 times
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: String function: 6BDC71AA appears 551 times
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: String function: 6BD98377 appears 56 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: String function: 002800F7 appears 655 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: String function: 00281D94 appears 59 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: String function: 00285A7C appears 73 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: String function: 00282F68 appears 462 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: String function: 0027FD12 appears 35 times
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: String function: 6BD980F9 appears 578 times
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: String function: 6BDB8EA6 appears 109 times
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: String function: 6BD63A0D appears 43 times
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: String function: 6BDC71AA appears 551 times
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: String function: 6BD98377 appears 56 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: String function: 00BF00F7 appears 655 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: String function: 00BF1D94 appears 59 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: String function: 00BF5A7C appears 73 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: String function: 00BF2F68 appears 462 times
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: String function: 00BEFD12 appears 35 times
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: String function: 00007FFE02B28840 appears 45 times
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: String function: 00007FF6F2E47720 appears 61 times
Source: pktbuilder_2.2.0.221_x64.exe Static PE information: invalid certificate
Source: pktbuilder_2.2.0.221_x64.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-SQVEQ.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-6CL3Q.tmp.1.dr Static PE information: Resource name: STYLE type: Zip archive data, at least v1.0 to extract, compression method=store
Source: is-6ME27.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-TV7H7.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-MU9KG.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-IBMCL.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-N2PNH.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-R1ORM.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-LTFPU.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-A0791.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-4NFF9.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-GICCJ.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-VNMR7.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-G6T73.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-I5GVU.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-UNBTF.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-SRQOT.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-K7EUC.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-EJN2E.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-ACOTL.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-GRBOB.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-TM1Q0.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-AMA4L.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-NVQA0.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-V5V1D.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-5LT4E.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-O3524.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-ON8S5.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-EVST5.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-98L2R.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-LDJV3.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-H8BG7.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-UCK6H.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-204E2.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-A4QG3.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-D3DE0.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-EOQ5J.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-AK0FJ.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-LIJ7L.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-RO4N7.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-9AT4K.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-137A4.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-HPT16.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-FGN4K.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-P4BS5.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-J333R.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-OSTLH.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-4JTCB.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-TJVGN.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-CDPHB.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-7HLRR.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-94JOE.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-ONOAO.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-0SH90.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-TE0LL.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-CERLA.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-5TLCD.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-C1Q4L.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-J4SII.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-DFJJC.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-D7T37.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-PRUKD.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-4FO5J.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-OP7SI.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-P0US6.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-D9MCF.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-V9MH3.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-6MCS0.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-2N91J.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-J3AUI.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-GTNR8.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-QOR6B.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-RF9ED.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-VN7RH.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-JOKG3.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-I79JV.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-4N0TG.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-DRCTN.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-S8I8I.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-O4KHO.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-U52S8.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-J9O9Q.tmp.1.dr Static PE information: No import functions for PE file found
Source: is-ENIAH.tmp.1.dr Static PE information: No import functions for PE file found
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1676351613.000000007FE35000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFileName vs pktbuilder_2.2.0.221_x64.exe
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000003.1675984733.00000000025D9000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFileName vs pktbuilder_2.2.0.221_x64.exe
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000002.2945541806.0000000002258000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamekernel32j% vs pktbuilder_2.2.0.221_x64.exe
Source: pktbuilder_2.2.0.221_x64.exe, 00000000.00000000.1674749191.00000000004C6000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFileName vs pktbuilder_2.2.0.221_x64.exe
Source: pktbuilder_2.2.0.221_x64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engine Classification label: sus26.spre.evad.winEXE@72/2394@0/0
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDACF6E __EH_prolog3,GetLastError,GetLastError,SetLastError,SetLastError,FormatMessageW,GetLastError,SetLastError,LocalFree, 8_2_6BDACF6E
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD94B28 AdjustTokenPrivileges, 8_2_6BD94B28
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD94B28 AdjustTokenPrivileges, 11_2_6BD94B28
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_002513BA GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle, 13_2_002513BA
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BC13BA GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle, 22_2_00BC13BA
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01004F6B InitializeSecurityDescriptor,InitializeAcl,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,SetSecurityDescriptorDacl,GetCurrentDirectoryA,GetSystemDirectoryA,QueryDosDeviceA,_strlwr,strstr,strstr,strstr,GetDiskFreeSpaceA,CryptAcquireContextA,sprintf,CryptGenRandom,sprintf,sprintf,CryptReleaseContext,GetSystemTime,SystemTimeToFileTime,DialogBoxParamA,DosDateTimeToFileTime,LocalFileTimeToFileTime,SetFileTime,CloseHandle,SendDlgItemMessageA,MoveFileExA,strstr,_stricmp,SendDlgItemMessageA,GetLastError,CreateFileA,SetFilePointer,SetFilePointer,SetEndOfFile,SetFilePointer, 7_2_01004F6B
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD84F48 CreateToolhelp32Snapshot,_memset,Process32FirstW,Process32NextW,CloseHandle, 8_2_6BD84F48
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDA6BEF __EH_prolog3,CoInitialize,CoCreateInstance,__CxxThrowException@8,CoUninitialize,SysFreeString, 8_2_6BDA6BEF
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDB7C0B LoadResource,LockResource,SizeofResource, 8_2_6BDB7C0B
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD8E813 StartServiceW, 8_2_6BD8E813
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Users\user\AppData\Local\Programs Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3512:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1928:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2000:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5492:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6916:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5952:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:396:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7060:120:WilError_03
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\VC_Redist_SetupMutex
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3912:120:WilError_03
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe File created: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Command line argument: pJ7 8_2_003749C0
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Command line argument: pJO 11_2_004F49C0
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File read: C:\Program Files\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: vcredist2015_x86.exe, 0000000D.00000003.2553454307.00000000012C1000.00000004.00000020.00020000.00000000.sdmp, vcredist2015_x86.exe, 0000000D.00000003.2550740989.0000000001285000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SELECT `WixDependency`.`WixDependency`, `WixDependencyProvider`.`Component_`, `WixDependency`.`ProviderKey`, `WixDependency`.`MinVersion`, `WixDependency`.`MaxVersion`, `WixDependency`.`Attributes` FROM `WixDependencyProvider`, `WixDependency`, `WixDependencyRef` WHERE `WixDependency`.`WixDependency` = `WixDependencyRef`.`WixDependency_` AND `WixDependencyProvider`.`WixDependencyProvider` = `WixDependencyRef`.`WixDependencyProvider_`SELECT `WixDependencyProvider`.`WixDependencyProvider`, `WixDependencyProvider`.`Component_`, `WixDependencyProvider`.`ProviderKey`, `WixDependencyProvider`.`Attributes` FROM `WixDependencyProvider`Failed to ignored dependency "%ls" to the string dictionary.;Failed to create the string dictionary.Failed to get the string value of the IGNOREDEPENDENCIES property.IGNOREDEPENDENCIESUnknownFailed to set the dependency name "%ls" into the message record.Failed to set the dependency key "%ls" into the message record.The dependency "%ls" is missing or is not the required version.Found dependent "%ls", name: "%ls".Failed to set the number of dependencies into the message record.Failed to set the message identifier into the message record.Not enough memory to create the message record.wixdepca.cppUnexpected message response %d from user or bootstrapper application.Failed to create the dependency record for message %d.Failed to enumerate all of the rows in the dependency query view.Failed to get WixDependency.Attributes.Failed to get WixDependency.MaxVersion.Failed to get WixDependency.MinVersion.Failed to get WixDependency.ProviderKey.Failed to get WixDependencyProvider.Component_.Failed to get WixDependency.WixDependency.Failed dependency check for %ls.Skipping dependency check for %ls because the component %ls is not being (re)installed.Failed to open the query view for dependencies.Failed to initialize the unique dependency string list.Failed to check if the WixDependency table exists.Skipping the dependency check since no dependencies are authored.WixDependencyFailed to enumerate all of the rows in the dependency provider query view.Failed to get WixDependencyProvider.Attributes.Failed to get WixDependencyProvider.ProviderKey.Failed to get WixDependencyProvider.Component.Failed to get WixDependencyProvider.WixDependencyProvider.Failed dependents check for %ls.Skipping dependents check for %ls because the component %ls is not being uninstalled.Failed to open the query view for dependency providers.Failed to check if the WixDependencyProvider table exists.Skipping the dependents check since no dependency providers are authored.WixDependencyProviderSkipping the dependencies check since IGNOREDEPENDENCIES contains "ALL".Failed to check if "ALL" was set in IGNOREDEPENDENCIES.ALLFailed to get the ignored dependents.Failed to ensure required dependencies for (re)installing components.ALLUSERSFailed to initialize the registry functions.Failed to initialize.WixDependencyRequireFailed to ensure absent dependents for uninstalling com
Source: Setup.exe String found in binary or memory: Pre-Installation Warnings:
Source: Setup.exe String found in binary or memory: Pre-Installation Warnings:
Source: vcredist2015_x86.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: vcredist2015_x64.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe File read: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe "C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe"
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Process created: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp "C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp" /SL5="$20422,63727098,781312,C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe"
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe "C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe" /q /norestart
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Process created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe c:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe /q /norestart
Source: unknown Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe "C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe" /q /norestart
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Process created: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe c:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe /q /norestart
Source: unknown Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe "C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe" /q /norestart
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Process created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe "C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe" /q /norestart -burn.unelevated BurnPipe.{6E791D85-9C4E-4EE6-AAEB-E0BB1FB3FCB8} {66DF9C74-890C-4C4F-849F-F210CA510BFE} 6740
Source: unknown Process created: C:\Windows\System32\VSSVC.exe C:\Windows\system32\vssvc.exe
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k swprv
Source: unknown Process created: C:\Windows\System32\SrTasks.exe C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1
Source: C:\Windows\System32\SrTasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe "C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe" /q /norestart
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Process created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe "C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe" /q /norestart -burn.unelevated BurnPipe.{F07E7E37-E584-48E8-8A43-7CE1D540358C} {ED92898B-936E-4C5A-9EC4-2F762E88C21F} 2916
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe "C:\Program Files\Colasoft Packet Builder\PktBuilder.exe" /regserver /lan en_us /autocheckupdate /regtool
Source: unknown Process created: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe "C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe" /burn.runonce
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe Process created: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe "C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe"
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe "C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe" /VERYSILENT
Source: C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe Process created: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp "C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp" /SL5="$704A2,425286,121344,C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe" /VERYSILENT
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -check_dll
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -c
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process created: C:\Windows\System32\pnputil.exe pnputil.exe -e
Source: C:\Windows\System32\pnputil.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -iw
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -i2
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s NetSetupSvc
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k DcomLaunch -p -s DeviceInstall
Source: C:\Windows\System32\svchost.exe Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{13d931c2-7f9b-1540-9f88-92c719c22a36}\CAPSADRV.inf" "9" "41c44f87b" "0000000000000158" "WinSta0\Default" "0000000000000170" "208" "C:\Program Files\CapsaDrv"
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net stop capsadrv
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net start capsadrv
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net start capsadrv
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 start capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -r2
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Process created: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp "C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp" /SL5="$20422,63727098,781312,C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe "C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe" /q /norestart Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe "C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe" /q /norestart Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe "C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe" /q /norestart Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe "C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe" /q /norestart Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe "C:\Program Files\Colasoft Packet Builder\PktBuilder.exe" /regserver /lan en_us /autocheckupdate /regtool Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process created: C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe "C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe" /VERYSILENT Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Process created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe c:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe /q /norestart Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Process created: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe c:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe /q /norestart
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Process created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe "C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe" /q /norestart -burn.unelevated BurnPipe.{6E791D85-9C4E-4EE6-AAEB-E0BB1FB3FCB8} {66DF9C74-890C-4C4F-849F-F210CA510BFE} 6740
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Process created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe "C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe" /q /norestart -burn.unelevated BurnPipe.{F07E7E37-E584-48E8-8A43-7CE1D540358C} {ED92898B-936E-4C5A-9EC4-2F762E88C21F} 2916
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe Process created: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe "C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe"
Source: C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe Process created: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp "C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp" /SL5="$704A2,425286,121344,C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe" /VERYSILENT
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -check_dll
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -c
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -iw
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -i2
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net start capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Program Files\CapsaDrv\DrvInstall.exe "C:\Program Files\CapsaDrv\drvinstall.exe" -n -r2
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process created: C:\Windows\System32\pnputil.exe pnputil.exe -e
Source: C:\Windows\System32\svchost.exe Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{13d931c2-7f9b-1540-9f88-92c719c22a36}\CAPSADRV.inf" "9" "41c44f87b" "0000000000000158" "WinSta0\Default" "0000000000000170" "208" "C:\Program Files\CapsaDrv"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net stop capsadrv
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop capsadrv
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net start capsadrv
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 start capsadrv
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: msftedit.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: windows.globalization.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: globinputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: windows.ui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: windowmanagementapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: inputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: licensemanagersvc.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: licensemanager.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: clipc.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: clusapi.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: feclient.dll Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: winmm.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: samcli.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: version.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: mpr.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: setupengine.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msi.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: secur32.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: sqmapi.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: wldp.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: profapi.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: msisip.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: srpapi.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: tsappcmp.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msisip.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: version.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: apphelp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: uxtheme.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: textshaping.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: textinputframework.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: ntmarta.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: clusapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: dnsapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: iphlpapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: wkscli.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: cscapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: netutils.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: cryptsp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: rsaenh.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: cryptbase.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: feclient.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Section loaded: iertutil.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: apphelp.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: acgenral.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: uxtheme.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: winmm.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: samcli.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msacm32.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: version.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: userenv.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: dwmapi.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: urlmon.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: mpr.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: sspicli.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: winmmbase.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: winmmbase.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: iertutil.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: srvcli.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: netutils.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: setupengine.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msi.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: winhttp.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: secur32.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: sqmapi.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msasn1.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: profapi.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: ntmarta.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: kernel.appcore.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: windows.storage.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: wldp.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msxml3.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: cryptsp.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: rsaenh.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: cryptbase.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: gpapi.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: msisip.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: srpapi.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: tsappcmp.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: netapi32.dll
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Section loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msisip.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: version.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: cabinet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: msi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wininet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: version.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: msasn1.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: msxml3.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: windows.storage.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wldp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: profapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: apphelp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: uxtheme.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: textinputframework.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: ntmarta.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: srclient.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: spp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: powrprof.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: vssapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: vsstrace.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: umpdc.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: usoapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: sxproxy.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: cryptsp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: rsaenh.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: cryptbase.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: msisip.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: gpapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: cryptnet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: iphlpapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: winnsi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: srpapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: tsappcmp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: netapi32.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wkscli.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: netutils.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: cabinet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: msi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wininet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: version.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: msasn1.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: msxml3.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: windows.storage.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wldp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: profapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: feclient.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: iertutil.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: uxtheme.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: textinputframework.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: ntmarta.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: windowscodecs.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: explorerframe.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: riched20.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: usp10.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: msls31.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Section loaded: textshaping.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: devobj.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: authz.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: virtdisk.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: bcd.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: fltlib.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: es.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: amsi.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: userenv.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: profapi.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: vss_ps.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: samcli.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: netutils.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: samlib.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: propsys.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: catsrvut.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: mfcsubs.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: sxs.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: msxml3.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: clusapi.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: dnsapi.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: iphlpapi.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: wkscli.dll
Source: C:\Windows\System32\VSSVC.exe Section loaded: cscapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: swprv.dll
Source: C:\Windows\System32\svchost.exe Section loaded: devobj.dll
Source: C:\Windows\System32\svchost.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\svchost.exe Section loaded: virtdisk.dll
Source: C:\Windows\System32\svchost.exe Section loaded: fltlib.dll
Source: C:\Windows\System32\svchost.exe Section loaded: wldp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exe Section loaded: amsi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: userenv.dll
Source: C:\Windows\System32\svchost.exe Section loaded: profapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: es.dll
Source: C:\Windows\System32\svchost.exe Section loaded: vss_ps.dll
Source: C:\Windows\System32\svchost.exe Section loaded: fveapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: fveapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: fveapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: fveapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: spp.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srclient.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ktmw32.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: wer.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: bcd.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: dsrole.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: msxml3.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vss_ps.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msisip.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: version.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: cabinet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: msi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wininet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: version.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: msasn1.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: msxml3.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: windows.storage.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wldp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: profapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: apphelp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: uxtheme.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: textinputframework.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: ntmarta.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: srclient.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: spp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: powrprof.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: vssapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: vsstrace.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: umpdc.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: cabinet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: msi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wininet.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: version.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: msasn1.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: msxml3.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: windows.storage.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wldp.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: profapi.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: feclient.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: iertutil.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: uxtheme.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: textinputframework.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: ntmarta.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: coremessaging.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: wintypes.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: windowscodecs.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: explorerframe.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: riched20.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: usp10.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: msls31.dll
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Section loaded: textshaping.dll
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Section loaded: apphelp.dll
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Section loaded: mfc140u.dll
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Section loaded: csxtp1631.dll
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Section loaded: csbcl.dll
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Section loaded: msvcp140.dll
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Section loaded: cspde.dll
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32 Jump to behavior
Source: Colasoft Packet Builder 2.2.lnk.1.dr LNK file: ..\..\..\Program Files\Colasoft Packet Builder\pktbuilder.exe
Source: Colasoft Packet Builder 2.2.lnk0.1.dr LNK file: ..\..\..\..\..\..\..\Program Files\Colasoft Packet Builder\pktbuilder.exe
Source: Colasoft Packet Builder 2.2.lnk1.1.dr LNK file: ..\..\..\..\..\..\Program Files\Colasoft Packet Builder\pktbuilder.exe
Source: Uninstall Colasoft Packet Builder 2.2.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files\Colasoft Packet Builder\unins000.exe
Source: Readme.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files\Colasoft Packet Builder\mui\en_us\ReadMe.txt
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Window found: window name: TMainForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Colasoft Capsa End User License AgreementCopyright (c) Colasoft. All rights reserved.This License Agreement is a legal contract between you (either as an individual or as an entity) and Colasoft ("COLASOFT") for the Colasoft Capsa and related add-ons ("SOFTWARE PRODUCT"). Please carefully read the following terms and conditions before using the Software Product. Installation or use of the SOFTWARE PRODUCT indicates your acceptance of this License Agreement.COPYRIGHTThe SOFTWARE PRODUCT and Documentation are copyrighted by COLASOFT and are protected by international copyright laws. The SOFTWARE PRODUCT contains copyrighted software of COLASOFT. All rights reserved. You agree not to remove any trademarks or copyright notices from the SOFTWARE PRODUCT and Documentations.LICENSE TYPES1. Single Seat Perpetual LicenseA Single Seat Perpetual License grants you the right to install and use the SOFTWARE PRODUCT on one single computer and provide access for an unlimited number of individuals. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first computer you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.2. 5 Seat LicenseA 5 Seat License grants you the right to install and use the SOFTWARE PRODUCT on five computers and provide access for an unlimited number of individuals with one single license key. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first five computers you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.NOT-FOR-RESALE COPIESIf the SOFTWARE PRODUCT is marked as a Not-For-Resale (NFR) copy you may not sell or transfer the usage license of the SOFTWARE PRODUCT for any kind of payment. An NFR copy of the SOFTWARE PRODUCT may only be used for purposes of demonstrating the SOFTWARE PRODUCT. With an NFR version of the SOFTWARE PRODUCT you may not make or distribute additional copies.DEMO VERSIONIf the SOFTWARE PRODUCT is marked as a demonstration version for the final user (DEMO) you must buy a legal license and delete all copies of the demo version after expiring the time limit. The demo version may be distributed freely by any kind of MEDIA Internet server BBS etc. as long as no changes are made and package content is not changed. FREE EDITIONIf the SOFTWARE PRODUCT is marked as a free edition for the final user (FREE) it provided you without charge. You may not use the SOFTWARE PRODUCT in your workplace or for commercial purpose. LIMITATION ON USEYou may not: permit other individuals to use the SOFTWARE PRODUCT except under the terms listed above; modify translate reverse engineer decompile decrypt extract disassemble or create der
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Colasoft Capsa End User License AgreementCopyright (c) Colasoft. All rights reserved.This License Agreement is a legal contract between you (either as an individual or as an entity) and Colasoft ("COLASOFT") for the Colasoft Capsa and related add-ons ("SOFTWARE PRODUCT"). Please carefully read the following terms and conditions before using the Software Product. Installation or use of the SOFTWARE PRODUCT indicates your acceptance of this License Agreement.COPYRIGHTThe SOFTWARE PRODUCT and Documentation are copyrighted by COLASOFT and are protected by international copyright laws. The SOFTWARE PRODUCT contains copyrighted software of COLASOFT. All rights reserved. You agree not to remove any trademarks or copyright notices from the SOFTWARE PRODUCT and Documentations.LICENSE TYPES1. Single Seat Perpetual LicenseA Single Seat Perpetual License grants you the right to install and use the SOFTWARE PRODUCT on one single computer and provide access for an unlimited number of individuals. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first computer you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.2. 5 Seat LicenseA 5 Seat License grants you the right to install and use the SOFTWARE PRODUCT on five computers and provide access for an unlimited number of individuals with one single license key. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first five computers you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.NOT-FOR-RESALE COPIESIf the SOFTWARE PRODUCT is marked as a Not-For-Resale (NFR) copy you may not sell or transfer the usage license of the SOFTWARE PRODUCT for any kind of payment. An NFR copy of the SOFTWARE PRODUCT may only be used for purposes of demonstrating the SOFTWARE PRODUCT. With an NFR version of the SOFTWARE PRODUCT you may not make or distribute additional copies.DEMO VERSIONIf the SOFTWARE PRODUCT is marked as a demonstration version for the final user (DEMO) you must buy a legal license and delete all copies of the demo version after expiring the time limit. The demo version may be distributed freely by any kind of MEDIA Internet server BBS etc. as long as no changes are made and package content is not changed. FREE EDITIONIf the SOFTWARE PRODUCT is marked as a free edition for the final user (FREE) it provided you without charge. You may not use the SOFTWARE PRODUCT in your workplace or for commercial purpose. LIMITATION ON USEYou may not: permit other individuals to use the SOFTWARE PRODUCT except under the terms listed above; modify translate reverse engineer decompile decrypt extract disassemble or create der
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Colasoft Capsa End User License AgreementCopyright (c) Colasoft. All rights reserved.This License Agreement is a legal contract between you (either as an individual or as an entity) and Colasoft ("COLASOFT") for the Colasoft Capsa and related add-ons ("SOFTWARE PRODUCT"). Please carefully read the following terms and conditions before using the Software Product. Installation or use of the SOFTWARE PRODUCT indicates your acceptance of this License Agreement.COPYRIGHTThe SOFTWARE PRODUCT and Documentation are copyrighted by COLASOFT and are protected by international copyright laws. The SOFTWARE PRODUCT contains copyrighted software of COLASOFT. All rights reserved. You agree not to remove any trademarks or copyright notices from the SOFTWARE PRODUCT and Documentations.LICENSE TYPES1. Single Seat Perpetual LicenseA Single Seat Perpetual License grants you the right to install and use the SOFTWARE PRODUCT on one single computer and provide access for an unlimited number of individuals. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first computer you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.2. 5 Seat LicenseA 5 Seat License grants you the right to install and use the SOFTWARE PRODUCT on five computers and provide access for an unlimited number of individuals with one single license key. You may NOT install and use the SOFTWARE PRODUCT on a computer other than the first five computers you installed the SOFTWARE PRODUCT on. For running this SOFTWARE PRODUCT on additional computers requires additional licenses.NOT-FOR-RESALE COPIESIf the SOFTWARE PRODUCT is marked as a Not-For-Resale (NFR) copy you may not sell or transfer the usage license of the SOFTWARE PRODUCT for any kind of payment. An NFR copy of the SOFTWARE PRODUCT may only be used for purposes of demonstrating the SOFTWARE PRODUCT. With an NFR version of the SOFTWARE PRODUCT you may not make or distribute additional copies.DEMO VERSIONIf the SOFTWARE PRODUCT is marked as a demonstration version for the final user (DEMO) you must buy a legal license and delete all copies of the demo version after expiring the time limit. The demo version may be distributed freely by any kind of MEDIA Internet server BBS etc. as long as no changes are made and package content is not changed. FREE EDITIONIf the SOFTWARE PRODUCT is marked as a free edition for the final user (FREE) it provided you without charge. You may not use the SOFTWARE PRODUCT in your workplace or for commercial purpose. LIMITATION ON USEYou may not: permit other individuals to use the SOFTWARE PRODUCT except under the terms listed above; modify translate reverse engineer decompile decrypt extract disassemble or create der
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Window detected: Number of UI elements: 19
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe Window detected: Number of UI elements: 19
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\unins000.dat Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-SQVEQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-N8PT0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-O8KO8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-S9K5O.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-U4N3E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-FTAR3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-FPF1L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-83JJP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-J304I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-GTJ7O.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-0E13V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-GDME8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-DKOJV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-FU1BO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-PDAAT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-8EHFU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-9E0NC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-P0E3Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-OKV67.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-6237I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-D18OI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-3330M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-N579M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-TL9NT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-B9V58.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-4L076.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\data Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\data\is-M5RD2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-1UONN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\data\is-O7UF7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-9V2FV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-KK3C2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-D4FHM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-CRRC6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-MI97R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-S9K6E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\is-0UF4L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TKILU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3ASFI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UCDVV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J6G3A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ETNA6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IOIRR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UNQ0D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-44OKD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QV0AN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SRNLF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LE8JF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-49IIN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4SMT8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S7GP5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M4F8T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N41CV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S94BH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DP4NL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KL6KG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-85O5U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SN03C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SK0LO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6E8DV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-G3FKB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SSTME.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RIUC6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-86DH3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F2S2V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8PQQI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LUA7M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NCBTK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A53GH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AAD9D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8N991.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MUKN9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0UJFQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BVH0Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U7V4U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-USI5Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PBN7I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-95M2E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D8K45.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U05L0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6IDIF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7DEK3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-59R3F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TH5KJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-P0UVC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S4SVH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PJNJK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U0ROA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CPJGV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AI1IF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4A3PB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CV2NT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JR8U0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CU8UM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-35MDD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QO4F5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1N8H8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-52PPT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NI8SH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0BNTQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-63T9E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N62TT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R1T7F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CCV7J.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BS9PB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QQ98D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-25430.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MR5K8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PSU7M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LCLR6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EO2NS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-33TFI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RDEF8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PM3RV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RKP2Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VTU99.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-T77UP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FSEKH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IQ7KJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SD2L3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-L97OV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HKVIJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7OLHU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HV6AR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I8GKL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DNS7U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NIMJJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AI467.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OE0SH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EKKA9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O3H6B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IIK6V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PH8FB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7NFJD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7Q4AU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-E49GS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SVUVS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KFS11.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NPDM3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H2GBM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M2PKR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-T7RKU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HDFGJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1AC34.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DF191.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SSIKR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-15MN5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ITL6U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BL8B5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-B7LAH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O40QH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LENAT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PT0U0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N9M3N.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TH1VH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I5F6P.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MTIOA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-55JI6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I5AUQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2D8M9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-53H4P.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AT6BL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ENF56.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DRSP5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VJH28.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FUF9T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EVAJD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-81FJ6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BPV3D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QI5AL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2U7U6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CHEC4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4NLF0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UR3FM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7S6EA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1KDFM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5RHVQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AMMUN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IA00G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-GJ6DK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2PC4I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IED1G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QOF5G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BALPN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1DB01.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9A15R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6KL23.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UOPBM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JSR8U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PJATD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EOVF1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PIDVA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O45A2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NQBU1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D3EP1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MIDKB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A1324.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KAU1C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-30S0S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2HDEG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UAM3T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N3159.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HSUR9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SMRLH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-35TM5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OQ9BD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-77JH0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PITL7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-C7CJI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LACPI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5V0UQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NHDTA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NHVAV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-Q8HPG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UEULF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SLQ1H.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-12HV2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TVSOU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EKQPM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TG0PK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1OM6J.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HSU9L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BP048.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JQG1C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0C9CB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BQ11C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VCS1S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LH2OH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-10AF1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9SNPS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8U4JA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2GV2Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-92G1E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SKBGS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-TEUDB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9HK7V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-L7UA9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A9985.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-732ON.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-B6OJP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6MT4B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7DG5E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DI5I5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AR7M0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LDDUC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7TVIG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PERAE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4L02A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SL1R2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-K54T2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BIV69.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8I1GI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VJFH8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LE9MT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A0OUE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1EASE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-B89BK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LQ1LO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-C92VM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O2O5M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-37J8U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M3OJC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O6GAP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9D0G3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F1ORV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-680DG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8TIKE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FGK3D.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-583BE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IRV5T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1I05E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-50QBB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PUFI4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-45T2A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-L0PQG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I3FNL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UA3UO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H6ICG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KFH4C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QT3S4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6D6K3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J3LI6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U0E7S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ELNGG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IVJ8T.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-C3955.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-CRLTL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-V6QGG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4KH7S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-T89R4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KTFIH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-G29RS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5T9FR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EVSDS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QPB78.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-L2DMD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1OSJG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NFRR4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-227GH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VIN7R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-40OPJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IM74L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J7NN5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-21URT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-92FST.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-79FG6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2O9NR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PD22B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AMDC5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SA67F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AOC3B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JJ1EU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-V3CA4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ALAOA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-GUJUE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J1UPD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7VDDH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U7OKC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-Q531S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MCQTH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MTD15.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-22LHG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KVDQC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JQJR2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KNP3N.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R0V9B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D618N.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VU2LN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-18780.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SDPPO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1691K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-V6PL8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8SAKO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ABT4C.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R7LDR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9R25E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LNA4L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4U3F1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NM1A5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HAQM1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9GM6I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-00N3F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A0O7A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VBKQO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LVUT5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-J40FD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PUSA1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DDJBB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H59V6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KNK4K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-Q8CB3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SP83J.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AV8NE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SN0OR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2K9N7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U6I38.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HTE4K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H6T5R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-UBUF5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0SRE1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S04PH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9JM9B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9337M.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8BNBM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-HL4SS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R0T54.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R559I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-GD080.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-01A9E.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9PKUT.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F7CHG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EVLIN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-07ADV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3I10F.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-IG1G9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BBPVH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8RAD5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D9INH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-P2JAK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9VH69.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7JKTR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OUNLS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-O0TP9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KKU2L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-86GAN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-U37H7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EHF91.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-EH0KD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M4KIH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-P1I3B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FQEQK.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BBJVA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F1182.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S3D9V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7222P.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9GCB4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2LJI1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6936S.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-N3JA9.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-M8L3I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6KSB7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R1VVP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-V9NDR.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-BUEOC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AOM2B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ULVUF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MTJU7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-18CTB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3TQQ6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-2FTGL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OR507.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-9EKA7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ASQ9G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KOV84.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0Q3CG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-COOQN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KFFQV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FL5QJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3SAFS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8KREJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-GJODE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-AGQ1R.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LGUB3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F789K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5R8JJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PEQRJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ISHIS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-5JKJI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6O2K6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-E8B9K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LMBG0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8ESO4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6MCA0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MD0HL.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OADV6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-6A272.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RJ53O.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-PKFTE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SGRH6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-769K5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1VS47.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4GSQP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-E9TAP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-11ON4.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-13624.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-II6RB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-4F94N.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0DKBO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-K6J88.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JANKV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-8A7BN.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-KSUHP.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-715LA.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-E4H1A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LUP0I.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-OSKCU.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QF6S3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-FNQU7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-ERTNV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-K4C4V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-F6U3B.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LIHDB.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-00PQM.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0GJ5L.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RQ65O.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-I0IKG.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-56S5G.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-0LBUO.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-RL3I5.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-D5CTE.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-R1495.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VQC3V.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-C9QB8.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-DMCLS.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-P08AC.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-QFQD2.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-MP47P.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-T6AFJ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LBR1U.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-NCCLQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A86IH.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-3HP0A.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-S0HSI.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-045TV.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LJ8A7.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-SSJ1Q.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-A3AR0.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-H8K98.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LD81K.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-LG9HQ.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-7PII1.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-11EVD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-JSHVF.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-VBHI3.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Directory created: C:\Program Files\Colasoft Packet Builder\fast_decoders\is-1MAAD.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Colasoft Packet Builder_is1 Jump to behavior
Source: pktbuilder_2.2.0.221_x64.exe Static file information: File size 64606936 > 1048576
Source: C:\Windows\System32\msiexec.exe File opened: c:\Windows\SysWOW64\msvcr100.dll
Source: pktbuilder_2.2.0.221_x64.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: \For Work\Source Code\CodeJock_XTP\Xtreme ToolkitPro v16.3.1\Workspace\Resource\ResourceEn\Release\vc140x64\CSXTPRes1631EnUs.pdb source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp, pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2939452166.000000000018C000.00000004.00000010.00020000.00000000.sdmp
Source: Binary string: sfxcab.pdb source: vcredist_x86.exe, vcredist_x86.exe, 00000007.00000000.2161836064.0000000001002000.00000020.00000001.01000000.00000009.sdmp, vcredist_x86.exe, 00000007.00000002.2281054939.0000000001002000.00000020.00000001.01000000.00000009.sdmp, vcredist_x64.exe, 0000000A.00000002.2402144549.0000000001002000.00000020.00000001.01000000.00000010.sdmp, vcredist_x64.exe, 0000000A.00000000.2281999628.0000000001002000.00000020.00000001.01000000.00000010.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSMFCEX.pdb66 GCTL source: pktbuilder.exe, 00000018.00000002.2731507197.00007FFE115F7000.00000002.00000001.01000000.0000001D.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSMFCEX.pdb source: pktbuilder.exe, 00000018.00000002.2731507197.00007FFE115F7000.00000002.00000001.01000000.0000001D.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSPCE.pdb--$GCTL source: pktbuilder.exe, 00000018.00000002.2730614552.00007FFE1025D000.00000002.00000001.01000000.0000001F.sdmp
Source: Binary string: D:\projects\capsa\output\x64_Release\pdb\csupd.pdb;;+GCTL source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\WixDepCA.pdb source: vcredist2015_x86.exe, 0000000D.00000003.2553454307.00000000012C1000.00000004.00000020.00020000.00000000.sdmp, vcredist2015_x86.exe, 0000000D.00000003.2550740989.0000000001285000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\burn.pdb`E source: vcredist2015_x86.exe, 0000000D.00000003.2542003899.0000000001266000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: patchhooks.pdb source: Setup.exe, 0000000B.00000003.2337000688.0000000000EA0000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2336872678.0000000000E91000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\projects\capsa\output\x64_Release\pdb\csupd.pdb source: pktbuilder_2.2.0.221_x64.tmp, 00000001.00000002.2964179831.0000000003A60000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: D:\projects\capsa\output\x64_release\pdb\PktBuilder_Free.pdb source: pktbuilder.exe, 00000018.00000002.2722918282.00007FF6F2E81000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSDOM.pdb source: pktbuilder.exe, 00000018.00000002.2727490152.00007FFE0C0B5000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSUPDATE.pdb::"GCTL source: pktbuilder.exe, 00000018.00000002.2727849048.00007FFE0CFA3000.00000002.00000001.01000000.00000026.sdmp
Source: Binary string: Setup.pdb source: Setup.exe, Setup.exe, 0000000B.00000002.2398101425.00000000004F1000.00000020.00000001.01000000.00000011.sdmp, Setup.exe, 0000000B.00000000.2305441126.00000000004F1000.00000020.00000001.01000000.00000011.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\burn.pdb` source: vcredist2015_x64.exe, 00000016.00000000.2613910378.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000016.00000002.2634548426.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000017.00000000.2616534305.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000017.00000002.2642599043.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: D:\projects\capsa\output\x64_release\pdb\PktBuilder_Free.pdbTT, source: pktbuilder.exe, 00000018.00000002.2722918282.00007FF6F2E81000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSDOM.pdb!! source: pktbuilder.exe, 00000018.00000002.2727490152.00007FFE0C0B5000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSUPDATE.pdb source: pktbuilder.exe, 00000018.00000002.2727849048.00007FFE0CFA3000.00000002.00000001.01000000.00000026.sdmp
Source: Binary string: sqmapi.pdb source: Setup.exe, Setup.exe, 0000000B.00000002.2400635663.000000006F861000.00000020.00000001.01000000.00000013.sdmp
Source: Binary string: SetupEngine.pdb source: Setup.exe, Setup.exe, 0000000B.00000002.2400246217.000000006BD41000.00000020.00000001.01000000.00000012.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSPCE.pdb source: pktbuilder.exe, 00000018.00000002.2730614552.00007FFE1025D000.00000002.00000001.01000000.0000001F.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\burn.pdb`* source: vcredist2015_x86.exe, 0000000D.00000000.2403274922.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000D.00000002.2607207772.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000E.00000002.2611419868.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000E.00000000.2404949754.000000000028B000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: E:\delivery\Dev\wix37\build\ship\x86\burn.pdb source: vcredist2015_x86.exe, 0000000D.00000000.2403274922.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000D.00000003.2542003899.0000000001266000.00000004.00000020.00020000.00000000.sdmp, vcredist2015_x86.exe, 0000000D.00000002.2607207772.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000E.00000002.2611419868.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x86.exe, 0000000E.00000000.2404949754.000000000028B000.00000002.00000001.01000000.00000014.sdmp, vcredist2015_x64.exe, 00000016.00000000.2613910378.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000016.00000002.2634548426.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000017.00000000.2616534305.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp, vcredist2015_x64.exe, 00000017.00000002.2642599043.0000000000BFB000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSPFE.pdb!! source: pktbuilder.exe, 00000018.00000002.2730254550.00007FFE1023A000.00000002.00000001.01000000.00000021.sdmp
Source: Binary string: D:\projects\libraries\output\x64_Release\pdb\CSPFE.pdb source: pktbuilder.exe, 00000018.00000002.2730254550.00007FFE1023A000.00000002.00000001.01000000.00000021.sdmp
Source: is-EOQ5J.tmp.1.dr Static PE information: 0x9A158DFF [Sat Dec 2 04:24:31 2051 UTC]
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_010029C2 GetSystemDirectoryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary, 7_2_010029C2
Source: pktbuilder_2.2.0.221_x64.exe Static PE information: section name: .didata
Source: pktbuilder_2.2.0.221_x64.tmp.0.dr Static PE information: section name: .didata
Source: is-SQVEQ.tmp.1.dr Static PE information: section name: .didata
Source: is-CPT4P.tmp.1.dr Static PE information: section name: .wixburn
Source: is-AAHES.tmp.1.dr Static PE information: section name: .wixburn
Source: is-GFLHN.tmp.1.dr Static PE information: section name: .00cfg
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_010065F3 push ecx; ret 7_2_01006603
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_00373DF5 push ecx; ret 8_2_00373E08
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDC7296 push ecx; ret 8_2_6BDC72A9
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDBE605 push ecx; ret 8_2_6BDBE618
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F841B89 push ecx; ret 8_2_6F841B9C
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F844821 push ecx; ret 8_2_6F844834
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_004F3DF5 push ecx; ret 11_2_004F3E08
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDC7296 push ecx; ret 11_2_6BDC72A9
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDBE605 push ecx; ret 11_2_6BDBE618
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F861B89 push ecx; ret 11_2_6F861B9C
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F864821 push ecx; ret 11_2_6F864834
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_0027A1F5 push ecx; ret 13_2_0027A208
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BEA1F5 push ecx; ret 22_2_00BEA208
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE02B31B58 push rbp; iretd 24_2_00007FFE02B31B59
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE02B318C1 push rbp; iretd 24_2_00007FFE02B318C2

Persistence and Installation Behavior

barindex
Source: C:\Windows\System32\msiexec.exe System file written: C:\Windows\System32\msvcp100.dll
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 Blob Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 Blob Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-PRUKD.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\ucrtbase.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-VN7RH.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140jpn.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-6237I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-errorhandling-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\3082\SetupResources.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfcm100u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Program Files\CapsaDrv\capsadrv.sys (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-J304I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\CapsaDrv\csdriverslib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-processthreads-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-ONOAO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-file-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-util-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-OI9CJ.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100u.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\1033\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-private-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\1040\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-processenvironment-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100rus_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-errorhandling-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100chs_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-namedpipe-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Program Files\CapsaDrv\is-PAURV.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100rus.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFENovell.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-string-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfcm100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-heap-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\CSXTP1631.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-datetime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-file-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\1036\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\System32\is-ILTFF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-JOKG3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-time-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-7K8CU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-console-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100enu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_vcomp100_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-GTNR8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\CSMFCEX.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\System32\CapsaDrv\is-RKF1F.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-IBMCL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-runtime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-TJVGN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFEObserver.pfm (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100enu_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-profile-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\1028\SetupResources.dll Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Users\user\AppData\Local\Temp\{13d931c2-7f9b-1540-9f88-92c719c22a36}\capsadrv.sys (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140ita.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcr100_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-94JOE.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.be\VC_redist.x86.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100deu_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-convert-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-D9MCF.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\msvcp100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-J4SII.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-5TLCD.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-heap-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-file-l2-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\wixstdba.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-utility-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-MU9KG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-FOGQI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-MTSE4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSHPL.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSAFT.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-rtlsupport-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\1041\SetupResources.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100fra.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfc140u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-O3524.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-EFV58.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-environment-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-FGN4K.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-processthreads-l1-1-1.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-C1Q4L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-S9K5O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFEA5VIEWS.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-4QAOF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-handle-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\msvcp140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-I5GVU.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfcm100u.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\3082\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-204E2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-GTJ7O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-D4FHM.tmp Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{fb1bf615-1342-3a4c-9a87-982272badb62}\SETD5C8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-9AT4K.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-util-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-AMA4L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\CSBCL.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100enu.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-R1ORM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\zlibwapi.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-conio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_atl100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140esn.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-N2PNH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-TL9NT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-PDAAT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-A4QG3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-DRCTN.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: 6b26cd.rbf (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Users\user\AppData\Local\Temp\is-6VMTE.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\mui\en_us\is-I79JV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-2N91J.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100deu.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-file-l2-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-0E13V.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-137A4.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-HPT16.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-H8BG7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-file-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSNPL.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-O4KHO.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100fra_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSNPCAP.pcm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\CSUPDATE.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100rus_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140cht.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\1040\SetupResources.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\SetupUi.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-synch-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-DKOJV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-synch-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100kor.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\concrt140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-time-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\zint.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-4JTCB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-OKV67.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-processenvironment-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\1028\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-QOR6B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-7HLRR.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_vcomp100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vcruntime140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-D3DE0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSPDE.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-DKF3J.tmp Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Users\user\AppData\Local\Temp\{13d931c2-7f9b-1540-9f88-92c719c22a36}\SETD1FF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-D0078.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-synch-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-EJN2E.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\ucrtbase.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100esn_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\cstre.dll (copy) Jump to dropped file
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe File created: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140chs.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-private-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\SetupUi.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\1036\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-TE0LL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSUPDATE.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-synch-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Program Files\CapsaDrv\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-rtlsupport-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-UNBTF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-LIJ7L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSCRL.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-S8I8I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-multibyte-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100ita.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSCrypto.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140fra.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\1041\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-sysinfo-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-locale-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-file-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-J333R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-locale-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\1049\SetupResources.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100cht_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-LDJV3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-4NFF9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-processthreads-l1-1-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-6ME27.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-NINLN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-B7ROS.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcr100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFEETHERPEEK.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-math-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSMFCEX.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSXTP1631.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-conio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-6MCS0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-ACOTL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\libcrypto-3-x64.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-timezone-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-TV7H7.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100fra_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-LTFPU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\CapsaDrv\cspcap.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\csdriverslib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-stdio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\cspcap.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-K4I7S.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-libraryloader-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100u_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\mui\en_us\pktbuilderres.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vccorlib140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-heap-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-debug-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-SN3QF.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100cht.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140deu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\vcamp140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\Common Files\Microsoft Shared\VC\msdia100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFEColasoft.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-4FO5J.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100ita.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSBCL.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-A0791.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\vcomp100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-9V2FV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-RO4N7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-localization-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfcm140u.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100cht_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSCODER.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\mui\en_us\CSXTPRes.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100esn.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-EOQ5J.tmp Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Windows\system32\DRIVERS\capsadrv.sys (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-01NBS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-memory-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-RF9ED.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100esn_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-B9V58.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\atl100.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\1031\SetupResources.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcp100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-V5V1D.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-TM1Q0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-AAHES.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\2052\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-filesystem-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-5UR7B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-SRQOT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-convert-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-GOTR0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-interlocked-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100jpn.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-namedpipe-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-KK3C2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-localization-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFELibpcapng.pfm (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\vcomp100.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\sqmapi.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100kor_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-datetime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\sqmapi.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\SetupEngine.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{fb1bf615-1342-3a4c-9a87-982272badb62}\capsadrv.sys (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\atl100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vcomp140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100chs.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcp100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\msvcr100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100cht.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-GFLHN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-J9O9Q.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\1031\SetupResources.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\2052\SetupResources.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140rus.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-4N0TG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\System32\CapsaDrv\is-T4O6N.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\1049\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\libcrypto-3-x64.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-9E0NC.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\1042\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\CSDOM.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-CERLA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-UCK6H.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-P0US6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\CSHPL.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-0KFTQ.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100u_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100jpn_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-N8PT0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-FDHP0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-N579M.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-0SH90.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100chs_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-OP7SI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Program Files\CapsaDrv\is-HGT66.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-U52S8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFEHPUN.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-interlocked-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-timezone-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-process-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfcm140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-J3AUI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\pthreadVC2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFEVisNetTraCap.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSPFL.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100kor.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-TOEPF.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\SetupEngine.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-CPT4P.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-5LT4E.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-debug-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100jpn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100u_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-K7EUC.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100ita_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100chs.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-AK0FJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-D18OI.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100u_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-98L2R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-6IUUH.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfc140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-stdio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100enu_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-NVQA0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSDOM.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-M8KH3.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Program Files\CapsaDrv\DrvInstall.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\libpng16.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe File created: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-O5MB7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\csupd.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-string-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100fra.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFEMSNetMon.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFESniffer.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-1UONN.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100deu_x64 Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\1033\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSPFE.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfcm100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-VNMR7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-string-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-runtime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-HQVH2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-GICCJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-8EHFU.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFELibpcap.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-multibyte-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-6CL3Q.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140enu.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-ON8S5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSPCE.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-SQVEQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-string-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-P0E3Q.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-process-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-memory-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\wixstdba.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-heap-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100esn.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-FU1BO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-handle-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-FR9QT.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100jpn_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-P4BS5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-processthreads-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-OSTLH.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100deu.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-profile-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\PFESunSnoop.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-NU4AC.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-G6T73.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: C:\ed5f2a4e8ef6d24ec9a1a7747620\1042\SetupResources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-GRBOB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-environment-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-H4KMN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Program Files\CapsaDrv\is-6R4FA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-EVST5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\CSFMT.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Users\user\AppData\Local\Temp\is-5KVRI.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-D7T37.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-math-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\CSNPL.dll (copy) Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Windows\System32\drivers\SETEBCE.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100kor_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-4L076.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100ita_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-3330M.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-ENIAH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-utility-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100rus.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-sysinfo-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140kor.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\System32\is-7BQUN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\modules\is-G18PT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\is-GDME8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\CSCoder.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-V9MH3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-filesystem-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-console-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-CDPHB.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_atl100_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-libraryloader-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-DFJJC.tmp Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140esn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100u_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100cht.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140deu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100ita_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100chs.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\vcamp140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140jpn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfcm100u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\CapsaDrv\csdriverslib.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100u_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfc140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100ita.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100enu_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100deu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\vcomp100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100u.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100u.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfcm140u.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100cht_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100rus_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100fra_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100rus_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100esn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140cht.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100fra.dll Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Windows\system32\DRIVERS\capsadrv.sys (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100chs_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100esn_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\atl100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100rus.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfcm100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcp100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100deu_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfcm100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100kor.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\concrt140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\System32\is-ILTFF.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100enu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_vcomp100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\System32\CapsaDrv\is-RKF1F.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_vcomp100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vcruntime140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140enu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100jpn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100enu_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\vcomp100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100kor_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140ita.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcr100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100esn_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100deu_x86 Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{fb1bf615-1342-3a4c-9a87-982272badb62}\capsadrv.sys (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vcomp140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\atl100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100chs.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100esn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcp100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140chs.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\msvcp100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\msvcr100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100cht.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100jpn_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100deu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100ita.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140fra.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140rus.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\System32\CapsaDrv\is-T4O6N.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100cht_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100fra.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfc140u.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100u_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100jpn_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcr100_x64 Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Windows\System32\drivers\SETEBCE.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100kor_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100ita_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100rus.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100chs_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\msvcp140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc140kor.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\System32\is-7BQUN.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfcm100u.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100fra_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\CapsaDrv\cspcap.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\csdriverslib.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfcm140.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{fb1bf615-1342-3a4c-9a87-982272badb62}\SETD5C8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp File created: C:\Windows\system32\cspcap.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100kor.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_atl100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\SysWOW64\mfc100jpn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\System32\mfc100enu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100u_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_atl100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vccorlib140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100cht_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100chs_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_atl100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100esn_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100enu_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100u_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100u_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100rus_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100kor_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100jpn_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100ita_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100fra_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100deu_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_vcomp100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcr100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcp100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100kor_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100fra_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100esn_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100enu_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100deu_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100cht_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100chs_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_atl100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100jpn_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100ita_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_vcomp100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcr100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100u_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100u_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100rus_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcp100_x64 Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E7A690 #1670,#1641,GetPrivateProfileStringW,#1501,#1033,#286,#1667,#1033,#1033,#1033,#1641,_waccess,#1033, 24_2_00007FF6F2E7A690
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe File created: C:\Users\user\AppData\Local\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_20241003_234245280-MSI_vc_red.msi.txt Jump to behavior
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe File created: C:\Users\user\AppData\Local\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_20241003_234257425-MSI_vc_red.msi.txt
Source: C:\Program Files\CapsaDrv\DrvInstall.exe File created: C:\Program Files\CapsaDrv\DrvInstall.log
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1033\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1041\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1042\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1028\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\2052\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1040\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1036\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1031\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\3082\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe File created: c:\bf2fcf75a8aa83f568baf6bb7854b9ea\1049\eula.rtf Jump to behavior
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1033\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1041\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1042\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1028\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\2052\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1040\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1036\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1031\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\3082\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe File created: c:\ed5f2a4e8ef6d24ec9a1a7747620\1049\eula.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1028\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1029\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1031\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1036\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1040\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1041\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1042\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1045\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1046\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1049\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1055\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\2052\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\3082\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1028\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1029\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1031\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1036\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1040\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1041\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1042\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1045\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1046\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1049\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\1055\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\2052\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\3082\license.rtf
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe File created: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1028\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1029\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1031\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1036\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1040\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1041\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1042\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1045\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1046\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1049\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1055\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\2052\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\3082\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1028\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1029\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1031\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1036\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1040\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1041\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1042\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1045\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1046\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1049\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\1055\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\2052\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\3082\license.rtf
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe File created: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\license.rtf
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Registry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\VSSetup Jump to behavior
Source: C:\Windows\System32\SrTasks.exe Registry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Colasoft Packet Builder Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Colasoft Packet Builder\Colasoft Packet Builder 2.2.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Colasoft Packet Builder\Uninstall Colasoft Packet Builder 2.2.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Colasoft Packet Builder\Readme.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Colasoft Packet Builder\Release Notes.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Colasoft Packet Builder\EULA.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Colasoft Packet Builder\Help.lnk Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net stop capsadrv
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD8E813 StartServiceW, 8_2_6BD8E813
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {23daf363-3020-4059-b3ae-dc4ad39fed19}
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {23daf363-3020-4059-b3ae-dc4ad39fed19}
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {23daf363-3020-4059-b3ae-dc4ad39fed19}
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {23daf363-3020-4059-b3ae-dc4ad39fed19}
Source: C:\Users\user\Desktop\pktbuilder_2.2.0.221_x64.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\VSSVC.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Colasoft Packet Builder\capsadrv_x64.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\System32\pnputil.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exe File opened / queried: scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-heap-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-PRUKD.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-debug-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-VN7RH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-SN3QF.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100cht.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140deu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\vcamp140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140jpn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Microsoft Shared\VC\msdia100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-errorhandling-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-6237I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Program Files\CapsaDrv\capsadrv.sys (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfcm100u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFEColasoft.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Windows\system32\CapsaDrv\csdriverslib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-J304I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-4FO5J.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-processthreads-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-ONOAO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-file-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-util-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100ita.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-OI9CJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-A0791.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\vcomp100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-9V2FV.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-private-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-RO4N7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-localization-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfcm140u.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100cht_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-processenvironment-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100rus_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100esn.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-EOQ5J.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-errorhandling-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Dropped PE file which has not been started: C:\Windows\system32\DRIVERS\capsadrv.sys (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100chs_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-01NBS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-memory-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-namedpipe-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-RF9ED.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100esn_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\atl100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-B9V58.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100rus.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFENovell.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-string-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfcm100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-heap-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcp100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-V5V1D.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-TM1Q0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-datetime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-file-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-filesystem-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Windows\System32\is-ILTFF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-JOKG3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-5UR7B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-time-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-console-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_vcomp100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100enu.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-SRQOT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-GTNR8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-convert-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-GOTR0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Windows\System32\CapsaDrv\is-RKF1F.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-IBMCL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-interlocked-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100jpn.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-runtime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-namedpipe-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-TJVGN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-KK3C2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFEObserver.pfm (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100enu_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-profile-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-localization-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\vcomp100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFELibpcapng.pfm (copy) Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{13d931c2-7f9b-1540-9f88-92c719c22a36}\capsadrv.sys (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100kor_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140ita.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-datetime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcr100_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-94JOE.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100deu_x86 Jump to dropped file
Source: C:\Windows\System32\drvinst.exe Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{fb1bf615-1342-3a4c-9a87-982272badb62}\capsadrv.sys (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\atl100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vcomp140.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100chs.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-convert-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_msvcp100_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\msvcp100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-D9MCF.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\msvcr100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-J4SII.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100cht.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-5TLCD.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-heap-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-GFLHN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-J9O9Q.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-file-l2-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\wixstdba.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-utility-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-MU9KG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-FOGQI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-MTSE4.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140rus.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-4N0TG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Windows\System32\CapsaDrv\is-T4O6N.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\CSAFT.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-9E0NC.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-rtlsupport-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100fra.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-CERLA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-O3524.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-UCK6H.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-P0US6.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100u_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100jpn_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-FDHP0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-EFV58.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-N579M.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-environment-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-FGN4K.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-processthreads-l1-1-1.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-0SH90.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-C1Q4L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\mui\en_us\is-S9K5O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFEA5VIEWS.pfm (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100chs_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-4QAOF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-handle-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-OP7SI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-I5GVU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Program Files\CapsaDrv\is-HGT66.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfcm100u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-U52S8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFEHPUN.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-interlocked-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-timezone-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-204E2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-GTJ7O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-process-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfcm140.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{fb1bf615-1342-3a4c-9a87-982272badb62}\SETD5C8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-D4FHM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-J3AUI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\pthreadVC2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-9AT4K.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFEVisNetTraCap.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-util-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100kor.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-AMA4L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-TOEPF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-5LT4E.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100jpn.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-debug-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100enu.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-R1ORM.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_atl100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-conio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140esn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100u_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-K7EUC.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100ita_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-N2PNH.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100chs.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-AK0FJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-TL9NT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-PDAAT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-D18OI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-A4QG3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-DRCTN.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: 6b26cd.rbf (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100u_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-98L2R.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\F6BA540115164363C8C2EE03A81A6A7A\14.0.23506\mfc140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-6IUUH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-6VMTE.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-stdio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100enu_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\mui\en_us\is-I79JV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-NVQA0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-2N91J.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100deu.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-M8KH3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-file-l2-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-0E13V.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-137A4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\libpng16.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-H8BG7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-HPT16.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-file-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-O4KHO.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100fra_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\CSNPCAP.pcm (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100rus_x86 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140cht.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-O5MB7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\csupd.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-string-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100fra.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFEMSNetMon.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFESniffer.pfm (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x64.exe Dropped PE file which has not been started: C:\ed5f2a4e8ef6d24ec9a1a7747620\SetupUi.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-synch-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-DKOJV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-1UONN.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100deu_x64 Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfcm100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-synch-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100kor.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\concrt140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-VNMR7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-string-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-time-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-runtime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-HQVH2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\zint.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-4JTCB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-GICCJ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-OKV67.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-processenvironment-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-8EHFU.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfcm100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-QOR6B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-multibyte-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFELibpcap.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-7HLRR.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-6CL3Q.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_vcomp100_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-D3DE0.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140enu.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-ON8S5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-DKF3J.tmp Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{13d931c2-7f9b-1540-9f88-92c719c22a36}\SETD1FF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-D0078.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-string-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-P0E3Q.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-synch-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-memory-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-EJN2E.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-process-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100esn_x86 Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\wixstdba.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-heap-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100esn.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140chs.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-FU1BO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-handle-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-private-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Dropped PE file which has not been started: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\SetupUi.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-TE0LL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-FR9QT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-synch-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-rtlsupport-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-UNBTF.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-LIJ7L.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100jpn_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-P4BS5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-processthreads-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-OSTLH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-S8I8I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-multibyte-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100deu.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc100ita.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-profile-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140fra.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFESunSnoop.pfm (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-NU4AC.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-sysinfo-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-G6T73.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-locale-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-GRBOB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-file-l1-2-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-locale-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-J333R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-environment-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-H4KMN.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100cht_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-4NFF9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-LDJV3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-processthreads-l1-1-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-6ME27.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-EVST5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-NINLN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-5KVRI.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-D7T37.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-crt-math-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_msvcr100_x64 Jump to dropped file
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Dropped PE file which has not been started: C:\Windows\System32\drivers\SETEBCE.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\PFEETHERPEEK.pfm (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100kor_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-4L076.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1926E8D15D0BCE53481466615F760A7F\10.0.40219\F_CENTRAL_mfc100ita_x64 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-math-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-3330M.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-ENIAH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-conio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\System32\mfc100rus.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-utility-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-6MCS0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-ACOTL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-sysinfo-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mfc140kor.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Windows\System32\is-7BQUN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\is-GDME8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\modules\is-G18PT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-timezone-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-TV7H7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-filesystem-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-V9MH3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-console-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100fra_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-LTFPU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Windows\system32\csdriverslib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Windows\system32\CapsaDrv\cspcap.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-CDPHB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-crt-stdio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Dropped PE file which has not been started: C:\Windows\system32\cspcap.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-K4I7S.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_atl100_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\api-ms-win-core-libraryloader-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\api-ms-win-core-libraryloader-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfcm100u_x86 Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Dropped PE file which has not been started: C:\Program Files\Colasoft Packet Builder\update1.0.4.3\is-DFJJC.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\$PatchCache$\Managed\DA87DA56D32DE1A33950A36EC55D222C\14.0.23506\vccorlib140.dll Jump to dropped file
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Evaded block: after key decision
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Evaded block: after key decision
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Evaded block: after key decision
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Evaded block: after key decision
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Evasive API call chain: GetModuleFileName,DecisionNodes,ExitProcess
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Evasive API call chain: GetModuleFileName,DecisionNodes,ExitProcess
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Evasive API call chain: GetModuleFileName,DecisionNodes,ExitProcess
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe API coverage: 3.9 %
Source: C:\Windows\System32\SrTasks.exe TID: 940 Thread sleep time: -290000s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_0027F805 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 0027F8A6h 13_2_0027F805
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_0027F805 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 0027F89Fh 13_2_0027F805
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BEF805 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 00BEF8A6h 22_2_00BEF805
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BEF805 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 00BEF89Fh 22_2_00BEF805
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe File Volume queried: C:\ FullSizeInformation
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File Volume queried: C:\Windows FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_010046B9 SendDlgItemMessageA,strstr,SetFileAttributesA,GetLastError,CopyFileA,SendDlgItemMessageA,strstr,SetFileAttributesA,CopyFileA,GetLastError,CopyFileA,SetFileAttributesA,SendDlgItemMessageA,_strlwr,GetLastError,MoveFileA,MoveFileA,_strlwr,strstr,FindFirstFileA,strrchr,SendDlgItemMessageA,DeleteFileA,Sleep,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,strchr,strrchr,SendDlgItemMessageA, 7_2_010046B9
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD75BC0 __EH_prolog3_GS,_memset,FindFirstFileW,FindNextFileW,FindClose, 8_2_6BD75BC0
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD74120 FindFirstFileW,GetFullPathNameW,SetLastError,_wcsrchr,_wcsrchr, 8_2_6BD74120
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F844281 memset,EnterCriticalSection,FindFirstFileW,LeaveCriticalSection,ctype,FindNextFileW,FindClose,ResetEvent,CreateThread,CloseHandle,GetLastError, 8_2_6F844281
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F858097 memset,memset,FindFirstFileW,DeleteFileW,GetLastError,FindNextFileW,FindClose, 8_2_6F858097
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD75BC0 __EH_prolog3_GS,_memset,FindFirstFileW,FindNextFileW,FindClose, 11_2_6BD75BC0
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD74120 FindFirstFileW,GetFullPathNameW,SetLastError,_wcsrchr,_wcsrchr, 11_2_6BD74120
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F864281 memset,EnterCriticalSection,FindFirstFileW,LeaveCriticalSection,ctype,FindNextFileW,FindClose,ResetEvent,CreateThread,CloseHandle,GetLastError, 11_2_6F864281
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F878097 memset,memset,FindFirstFileW,DeleteFileW,GetLastError,FindNextFileW,FindClose, 11_2_6F878097
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_00286D15 _memset,_memset,GetFileAttributesW,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,GetLastError,GetLastError,GetLastError,FindClose, 13_2_00286D15
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_00285D81 _memset,FindFirstFileW,FindClose, 13_2_00285D81
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_00268E6E _memset,FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 13_2_00268E6E
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BF6D15 _memset,_memset,GetFileAttributesW,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,GetLastError,GetLastError,GetLastError,FindClose, 22_2_00BF6D15
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BF5D81 _memset,FindFirstFileW,FindClose, 22_2_00BF5D81
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BD8E6E _memset,FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 22_2_00BD8E6E
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDA0D5E __EH_prolog3_GS,GetModuleHandleW,GetLastError,GetSystemInfo,GetNativeSystemInfo,GetLastError,GetLastError,GetLastError,_memset,GetNativeSystemInfo,GetLastError, 8_2_6BDA0D5E
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\NULL
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\NULL
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\NULL
Source: VSSVC.exe, 00000010.00000003.2627594262.0000019DD9260000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
Source: SrTasks.exe, 00000013.00000003.2700153181.000002197F2BE000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: WORKGROUPVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:((
Source: svchost.exe, 00000011.00000003.2524278738.00000205C3674000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: svchost.exe, 00000011.00000002.2949001475.00000205C3656000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000
Source: svchost.exe, 00000011.00000002.2948387144.00000205C362B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \Device\HarddiskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:536
Source: svchost.exe, 00000011.00000002.2951539148.00000205C3672000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: pktbuilder.exe, 00000018.00000003.2687876480.0000021528F2C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: "VMware, Inc."
Source: svchost.exe, 00000011.00000002.2951539148.00000205C3672000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: $@\\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}}
Source: pktbuilder.exe, 00000018.00000003.2694508100.00000215282BC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware Lab Manager
Source: pktbuilder.exe, 00000018.00000003.2687876480.0000021528F2C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: "VMware, Inc.""VMware, Inc."PARROT SAPARROT SASIEMENS AGCIESSESony Corporation"HUAWEI TECHNOLOGIES CO.,LTD""BBK EDUCATIONAL ELECTRONICS CORP.,LTD."Wistron Neweb CorporationZenith Electronics CorporationWistron Neweb CorporationWistron Neweb CorporationWistron Neweb Corporation"Universal Global Scientific Industrial Co., Ltd."Wistron Neweb CorporationTechnicolor CH USA Inc.Technicolor CH USA Inc."SHENZHEN RF-LINK TECHNOLOGY CO.,LTD."Sercomm Corporation.SMC Corporation
Source: svchost.exe, 00000011.00000002.2951539148.00000205C3672000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: (@\??\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: SrTasks.exe, 00000013.00000003.2713474138.000002197F2C3000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \Device\HarddiskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:\
Source: svchost.exe, 00000011.00000002.2951539148.00000205C3672000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: $@\??\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: pktbuilder.exe, 00000018.00000003.2694508100.00000215282BC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: TTE PCF encapsulates all protocol-related information.VMLABVMware Lab ManagerVMLABVMLAB uses VLAN to build tunnel transmission protected configurations between two different hosts.VNTAGVN-TagVNTAGVNTAG is used for connection,association and perception of virtual machines and external virtualization networks.WAIWAI ProtocolWAIwireless local area network (WLAN) authentication infrastructure WAI security scheme that is used for the identity authentication and key management in a WLAN.WRETH
Source: VSSVC.exe, 00000010.00000003.2562285612.0000019DD9240000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: pEFI VMware Virtual SATA CDROM
Source: svchost.exe, 00000011.00000002.2950987914.00000205C3658000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ,@SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000 13
Source: VSSVC.exe, 00000010.00000003.2627594262.0000019DD9260000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: -be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
Source: svchost.exe, 00000011.00000003.2524170173.00000205C367C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: SrTasks.exe, 00000013.00000003.2568798031.000002197F2C0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \Device\HarddiskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
Source: VSSVC.exe, 00000010.00000003.2605195156.0000019DD9240000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000
Source: svchost.exe, 00000011.00000002.2951539148.00000205C3672000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: (@\\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe API call chain: ExitProcess graph end node
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe API call chain: ExitProcess graph end node
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe API call chain: ExitProcess graph end node
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe API call chain: ExitProcess graph end node
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Process information queried: ProcessInformation Jump to behavior
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_003745BE _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 8_2_003745BE
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E7CB28 InitializeCriticalSectionEx,GetLastError,IsDebuggerPresent,OutputDebugStringW, 24_2_00007FF6F2E7CB28
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDBCB2B VirtualProtect ?,-00000001,00000104,? 8_2_6BDBCB2B
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_010029C2 GetSystemDirectoryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary, 7_2_010029C2
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01005899 InitializeCriticalSectionAndSpinCount,#17,GetProcessHeap,CreateEventA,CreateEventA,CreateEventA,CreateThread,WaitForSingleObject,SendDlgItemMessageA,Sleep,ShowWindow,SetParent,SendDlgItemMessageA,SendDlgItemMessageA,SendDlgItemMessageA,ShowWindow,LoadStringA,LoadStringA,SendDlgItemMessageA,SendDlgItemMessageA,SendDlgItemMessageA,SendDlgItemMessageA,SendDlgItemMessageA,ShowWindow,CreateFileA,GetFileSize,ReadFile,CloseHandle,DeleteFileA,SendDlgItemMessageA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,ExpandEnvironmentStringsA,CreateProcessA,ShowWindow,WaitForSingleObject,GetExitCodeProcess,CloseHandle,ShowWindow,LoadStringA,MessageBoxA,DeleteCriticalSection,ExitProcess, 7_2_01005899
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process token adjusted: Debug
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_010062FF SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 7_2_010062FF
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_003745BE _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 8_2_003745BE
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_00372BA5 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 8_2_00372BA5
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD97462 __EH_prolog3,GetModuleHandleW,GetProcAddress,SetThreadStackGuarantee,SetUnhandledExceptionFilter,GetCommandLineW, 8_2_6BD97462
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDBEF0A _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 8_2_6BDBEF0A
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BDBB431 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 8_2_6BDBB431
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6F84171F SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 8_2_6F84171F
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_004F2BA5 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 11_2_004F2BA5
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_004F45BE _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 11_2_004F45BE
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BD97462 __EH_prolog3,GetModuleHandleW,GetProcAddress,SetThreadStackGuarantee,SetUnhandledExceptionFilter,GetCommandLineW, 11_2_6BD97462
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDBEF0A _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 11_2_6BDBEF0A
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6BDBB431 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 11_2_6BDBB431
Source: C:\ed5f2a4e8ef6d24ec9a1a7747620\Setup.exe Code function: 11_2_6F86171F SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 11_2_6F86171F
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_002790B2 SetUnhandledExceptionFilter, 13_2_002790B2
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_0027851A IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 13_2_0027851A
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_0027A71C _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 13_2_0027A71C
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BE90B2 SetUnhandledExceptionFilter, 22_2_00BE90B2
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BE851A IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 22_2_00BE851A
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Code function: 22_2_00BEA71C _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 22_2_00BEA71C
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E7C508 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 24_2_00007FF6F2E7C508
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E7C7CC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 24_2_00007FF6F2E7C7CC
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FF6F2E7C6E4 SetUnhandledExceptionFilter, 24_2_00007FF6F2E7C6E4
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE0177F5A0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 24_2_00007FFE0177F5A0
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Code function: 24_2_00007FFE02C152E8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 24_2_00007FFE02C152E8
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Program Files\CapsaDrv\DrvInstall.exe Process created: C:\Windows\System32\pnputil.exe pnputil.exe -e
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net stop capsadrv
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop capsadrv
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net start capsadrv
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 start capsadrv
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01004F6B InitializeSecurityDescriptor,InitializeAcl,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,SetSecurityDescriptorDacl,GetCurrentDirectoryA,GetSystemDirectoryA,QueryDosDeviceA,_strlwr,strstr,strstr,strstr,GetDiskFreeSpaceA,CryptAcquireContextA,sprintf,CryptGenRandom,sprintf,sprintf,CryptReleaseContext,GetSystemTime,SystemTimeToFileTime,DialogBoxParamA,DosDateTimeToFileTime,LocalFileTimeToFileTime,SetFileTime,CloseHandle,SendDlgItemMessageA,MoveFileExA,strstr,_stricmp,SendDlgItemMessageA,GetLastError,CreateFileA,SetFilePointer,SetFilePointer,SetEndOfFile,SetFilePointer, 7_2_01004F6B
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01003D02 AllocateAndInitializeSid,GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetTokenInformation,GetLengthSid,GetTokenInformation,GetLengthSid, 7_2_01003D02
Source: Setup.exe, 00000008.00000003.2212756798.0000000001520000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000008.00000003.2212623730.0000000001520000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000008.00000003.2212825451.0000000001534000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Program Managerc
Source: Setup.exe, 0000000B.00000003.2334526337.0000000000E20000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2334680081.0000000000E3F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [2580] [explorer.exe] [Program Manager] [Visible]QK
Source: Setup.exe, 00000008.00000003.2212701628.00000000014D5000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000008.00000003.2212866353.00000000014D8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [2580] [explorer.exe] [Program Manager] [Visible]ble]w
Source: Setup.exe, 0000000B.00000003.2335107993.0000000000E45000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: k17[2580] [explorer.exe] [Program Manager] [Visible]QK
Source: Setup.exe, 0000000B.00000003.2397494438.0000000000E16000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2334632252.0000000000E63000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 0000000B.00000003.2397706492.0000000000E43000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Program Manager9-|
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-DTJLB.tmp\pktbuilder_2.2.0.221_x64.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Queries volume information: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\logo.png VolumeInformation
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x64.exe Queries volume information: C:\Users\user\AppData\Local\Temp\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}\.ba1\logo.png VolumeInformation
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Queries volume information: C:\Program Files\Colasoft Packet Builder\data\cstre.ctd VolumeInformation
Source: C:\Program Files\Colasoft Packet Builder\pktbuilder.exe Queries volume information: C:\Program Files\Colasoft Packet Builder\data\manuf VolumeInformation
Source: C:\ProgramData\Package Cache\{23daf363-3020-4059-b3ae-dc4ad39fed19}\VC_redist.x86.exe Queries volume information: C:\Users\user\AppData\Local\Temp\{23daf363-3020-4059-b3ae-dc4ad39fed19}\.ba1\logo.png VolumeInformation
Source: C:\Windows\System32\drvinst.exe Queries volume information: C:\Windows\System32\DriverStore\Temp\{fb1bf615-1342-3a4c-9a87-982272badb62}\capsadrv.cat VolumeInformation
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_002535AD ConvertStringSecurityDescriptorToSecurityDescriptorW,GetLastError,CreateNamedPipeW,CreateNamedPipeW,GetLastError,CloseHandle,LocalFree,CreateNamedPipeW,GetLastError, 13_2_002535AD
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01004F6B InitializeSecurityDescriptor,InitializeAcl,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,SetSecurityDescriptorDacl,GetCurrentDirectoryA,GetSystemDirectoryA,QueryDosDeviceA,_strlwr,strstr,strstr,strstr,GetDiskFreeSpaceA,CryptAcquireContextA,sprintf,CryptGenRandom,sprintf,sprintf,CryptReleaseContext,GetSystemTime,SystemTimeToFileTime,DialogBoxParamA,DosDateTimeToFileTime,LocalFileTimeToFileTime,SetFileTime,CloseHandle,SendDlgItemMessageA,MoveFileExA,strstr,_stricmp,SendDlgItemMessageA,GetLastError,CreateFileA,SetFilePointer,SetFilePointer,SetEndOfFile,SetFilePointer, 7_2_01004F6B
Source: C:\Program Files\Colasoft Packet Builder\vcredist2015_x86.exe Code function: 13_2_0028019C LookupAccountNameW,LookupAccountNameW,GetLastError,GetLastError,GetLastError,LookupAccountNameW,GetLastError, 13_2_0028019C
Source: C:\bf2fcf75a8aa83f568baf6bb7854b9ea\Setup.exe Code function: 8_2_6BD978FB __EH_prolog3_GS,GetCommandLineW,_memset,GetTimeZoneInformation,GetThreadLocale, 8_2_6BD978FB
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Code function: 7_2_01003972 OpenEventA,WaitForSingleObject,CloseHandle,Sleep,LoadLibraryA,GetProcAddress,WaitForSingleObject,GetLastError,InitiateSystemShutdownA,GetLastError,WaitForSingleObject,GetLastError,GetVersionExA,GetVersionExA,GetVersionExA,GetSystemDirectoryA,strchr,CreateFileA,FlushFileBuffers,CloseHandle,NtShutdownSystem,FreeLibrary, 7_2_01003972
Source: C:\Program Files\Colasoft Packet Builder\vcredist_x86.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
Source: C:\Users\user\AppData\Local\Temp\is-CS2F4.tmp\capsadrv_x64.tmp Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /C net stop capsadrv
No contacted IP infos