Windows Analysis Report
geosetter_setup.exe

Overview

General Information

Sample name: geosetter_setup.exe
Analysis ID: 1546439
MD5: 6c8aac98ac0f743037c412b513a6a3a6
SHA1: e9b08b023e456bb39a20209e4a288cab1740b0a5
SHA256: 64d508b33c50c5a9fd695c0b328dab5519703db96c6e4580b8934c39431876ab
Infos:

Detection

Score: 24
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Signatures

Found API chain indicative of debugger detection
Queries Google from non browser process on port 80
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query locales information (e.g. system language)
Contains functionality to shutdown / reboot the system
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Registers a DLL
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Classes Autorun Keys Modification
Sleep loop found (likely to delay execution)
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC0DD40 win32_crypt,Perl_get_context, 15_2_6DC0DD40
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION GeoSetter.exe Jump to behavior
Source: geosetter_setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.DisclaimerThis software is provided "as-is". No warranty of any kind is expressed or implied. You use at your own risk. The author will not be liable for data loss damages loss of profits or any other kind of loss while using or misusing this software.FreewareThis program is freeware - that means you can download and copy it. You can even use it for commercial purposes however the sale of this software is prohibited.If you are an editor and wish to include GeoSetter on a magazine's CD or DVD please contact me.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.DisclaimerThis software is provided "as-is". No warranty of any kind is expressed or implied. You use at your own risk. The author will not be liable for data loss damages loss of profits or any other kind of loss while using or misusing this software.FreewareThis program is freeware - that means you can download and copy it. You can even use it for commercial purposes however the sale of this software is prohibited.If you are an editor and wish to include GeoSetter on a magazine's CD or DVD please contact me.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: unknown HTTPS traffic detected: 130.15.24.27:443 -> 192.168.2.5:49980 version: TLS 1.2
Source: geosetter_setup.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00476120 FindFirstFileA,FindNextFileA,FindClose, 1_2_00476120
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004531A4 FindFirstFileA,GetLastError, 1_2_004531A4
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004648D0 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_004648D0
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00464D4C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_00464D4C
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00463344 FindFirstFileA,FindNextFileA,FindClose, 1_2_00463344
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0049998C FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose, 1_2_0049998C
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC0AEB0 win32_opendir,strlen,Perl_safesyscalloc,strcpy,MultiByteToWideChar,Perl_get_context,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,strlen,Perl_safesysmalloc,strcpy,GetLastError,_errno,WideCharToMultiByte,_errno,_errno,Perl_safesysfree,_errno,_errno, 15_2_6DC0AEB0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC0BB70 win32_longpath,strcpy,FindFirstFileA,strcpy,FindClose,_errno,FindClose,_errno, 15_2_6DC0BB70
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_70845F80 PL_charclass,wcscpy,FindFirstFileW,wcslen,wcscpy,FindClose,_errno,FindClose,_errno,toupper, 15_2_70845F80
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_70845BA0 PL_charclass,_mbscpy,FindFirstFileA,_mbscpy,FindClose,toupper,_errno,FindClose,_errno, 15_2_70845BA0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6560A76C Perl_get_context,Perl_get_context,Perl_get_context,GetLogicalDriveStringsA,Perl_get_context,Perl_get_context,Perl_get_context,Perl_get_context,Perl_get_context,Perl_sv_newmortal,Perl_get_context,Perl_sv_setuv,Perl_get_context,Perl_get_context,Perl_get_context,Perl_get_context,Perl_get_context, 15_2_6560A76C
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData\Local\Microsoft\Windows Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData\Local\Microsoft Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData\Local Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData\Local\Microsoft\Windows\History\desktop.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 15_2_6DC22F60

Networking

barindex
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe HTTP traffic: GET /v3/map_google.html HTTP/1.1 Accept: */* Accept-Language: en-CH User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0) Accept-Encoding: gzip, deflate Host: map.geosetter.de Connection: Keep-Alive
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe HTTP traffic: GET /v3/json3.js HTTP/1.1 Accept: */* Referer: http://map.geosetter.de/v3/map_google.html Accept-Language: en-CH User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0) Accept-Encoding: gzip, deflate Host: map.geosetter.de Connection: Keep-Alive
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe HTTP traffic: GET /v3/leaflet/leaflet.css HTTP/1.1 Accept: */* Referer: http://map.geosetter.de/v3/map_google.html Accept-Language: en-CH User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0) Accept-Encoding: gzip, deflate Host: map.geosetter.de Connection: Keep-Alive
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe HTTP traffic: GET /v3/leaflet/leaflet.js HTTP/1.1 Accept: */* Referer: http://map.geosetter.de/v3/map_google.html Accept-Language: en-CH User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0) Origin: http://map.geosetter.de Accept-Encoding: gzip, deflate Host: map.geosetter.de Connection: Keep-Alive
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe HTTP traffic: GET /v3/img/crosshair.gif HTTP/1.1 Accept: */* Referer: http://map.geosetter.de/v3/map_google.html Accept-Language: en-CH User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0) Accept-Encoding: gzip, deflate Host: map.geosetter.de Connection: Keep-Alive
Source: Joe Sandbox View ASN Name: DE-WEBGOwwwwebgodeDE DE-WEBGOwwwwebgodeDE
Source: Joe Sandbox View JA3 fingerprint: b22b3950835f7eba2f3be0917e4f949e
Source: Network traffic Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.12.23.50:443 -> 192.168.2.5:49705
Source: Network traffic Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.12.23.50:443 -> 192.168.2.5:49918
Source: global traffic HTTP traffic detected: GET /~phil/exiftool/rss.xml HTTP/1.1Pragma: no-cacheHost: owl.phy.queensu.caAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Encoding: identityUser-Agent: Mozilla/3.0 (compatible; Indy Library)
Source: global traffic HTTP traffic detected: GET /v3/map_google.html HTTP/1.1Accept: */*Accept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Accept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /v3/json3.js HTTP/1.1Accept: */*Referer: http://map.geosetter.de/v3/map_google.htmlAccept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Accept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /v3/leaflet/leaflet.css HTTP/1.1Accept: */*Referer: http://map.geosetter.de/v3/map_google.htmlAccept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Accept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /v3/leaflet/leaflet.js HTTP/1.1Accept: */*Referer: http://map.geosetter.de/v3/map_google.htmlAccept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Origin: http://map.geosetter.deAccept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /v3/img/crosshair.gif HTTP/1.1Accept: */*Referer: http://map.geosetter.de/v3/map_google.htmlAccept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Accept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC12390 win32_recvfrom,_get_osfhandle,recvfrom,win32_getpeername,WSAGetLastError,_errno,SetLastError, 15_2_6DC12390
Source: global traffic HTTP traffic detected: GET /~phil/exiftool/rss.xml HTTP/1.1Pragma: no-cacheHost: owl.phy.queensu.caAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Encoding: identityUser-Agent: Mozilla/3.0 (compatible; Indy Library)
Source: global traffic HTTP traffic detected: GET /v3/map_google.html HTTP/1.1Accept: */*Accept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Accept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /v3/json3.js HTTP/1.1Accept: */*Referer: http://map.geosetter.de/v3/map_google.htmlAccept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Accept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /v3/leaflet/leaflet.css HTTP/1.1Accept: */*Referer: http://map.geosetter.de/v3/map_google.htmlAccept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Accept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /v3/leaflet/leaflet.js HTTP/1.1Accept: */*Referer: http://map.geosetter.de/v3/map_google.htmlAccept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Origin: http://map.geosetter.deAccept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /v3/img/crosshair.gif HTTP/1.1Accept: */*Referer: http://map.geosetter.de/v3/map_google.htmlAccept-Language: en-CHUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/7.0)Accept-Encoding: gzip, deflateHost: map.geosetter.deConnection: Keep-Alive
Source: global traffic DNS traffic detected: DNS query: map.geosetter.de
Source: global traffic DNS traffic detected: DNS query: owl.phy.queensu.ca
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://abc.net.au/local/news/olympics/1999/07/item19990728112314_1.ht
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://abc.net.au/news/olympics/1999/06/item19990601114608_1.htm
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://abc.net.au/news/olympics/1999/07/item19990719151754_1.htm
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://abc.net.au/news/regionals/brokenh/monthly/regbrok-21jul1999-6.htm
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://abc.net.au/news/regionals/neweng/monthly/regeng-22jul1999-1.ht
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://actualidad.terra.es/sociedad/articulo/cuba_llama_ahorrar_energia_cambio_1957044.htm
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://aif.az/docs/daylight_res.pdf
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://allafrica.com/stories/200703300178.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://almanakka.helsinki.fi/aikakirja/Aikakirja2007kokonaan.pdf
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://api.geonames.org
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ar.clarin.com/diario/2001-06-06/e-01701.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ar.clarin.com/diario/2001-06-06/e-01701.htmZ
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ar.clarin.com/diario/2001-06-12/s-03501.htm
Source: GeoSetter.exe, 00000007.00000003.2483666998.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://arabic.pnn.ps/index.php?option=com_content&task=view&id=508
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://arabic.pnn.ps/index.php?option=com_content&task=view&id=50850
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://bdnews24.com/details.php?id=85889&cid=2
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://bdnews24.com/details.php?id=85889&cid=H
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://bdnews24.com/details.php?id=85889&cid=H#
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://bmockbe.ru/events/?ID=7583
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://bsalsa.com/
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=4150
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://cl.invertia.com/noticias/noticia.aspx?idNoticia=200801171849_EFE_ET4373&idtel
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://club.telepolis.com/silverpointdev/sptbxlib/
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://dailymailnews.com/200808/28/news/dmbrn03.htH
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://dailymailnews.com/200808/28/news/dmbrn03.html
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://diario.elmercurio.com/2011/03/28/_portada/_portada/noticias/7565897A-CA86-49E6-9E03-660B21A48
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://dir.gis.nsw.gov.au/cgi-bin/genobject/document/other/daylightsaving/tigGmZ
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://earth.google.com/kml/2.1
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483607874.0000000009604000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://eng.gateway.kg/cgi-bin/page.pl?id=1&story_name=doc9979.shtml
Source: GeoSetter.exe, 00000007.00000003.2483666998.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://english.pnn.ps/index.php?option=com_content&task=view&id=596&Itemid
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://english.pnn.ps/index.php?option=com_content&task=view&id=596&Itemid=5
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://english.pnn.ps/index.php?option=com_content&task=view&id=596&Itemid=5Z
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://eros.usgs.gov/#/Find_Data/Products_and_Data_Available/gtopo30_info
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095C8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://etan.org/et99c/december/26-31/30ETMAY.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:32000L0084:EN:NOT
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://g1.globo.com/bahia/noticia/2011/10/governador-jaques-wagner-confirma-horario-de-verao-na-bahi
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://home.no.net/janmayen/history.htm
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://in.reuters.com/article/southAsiaNews/idINIndia-40017620090601
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://in.reuters.com/article/southAsiaNews/idINIndia-400176200906d
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://inms-ienm.nrc-cnrc.gc.ca/images/time_services/TZ01SSE.j
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://inms-ienm.nrc-cnrc.gc.ca/images/time_services/TZ01SWE.j
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://jornale.com.br/index.php?option=com_content&task=view&id=13530&Itemid=54
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://jornale.com.br/index.php?option=com_content&task=view&id=13530&Itemid=5t%
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://madExcept.com
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://madExcept.comU
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://map.geosetter.de/v3/map_google.html
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://map.geosetter.de/v3/map_google.htmlSV
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://maps.google.com
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://media.enet.cu/radioreloj
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://media.enet.cu/radiorelot
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://met.no/met/met_lex/q_u/sommertid.html
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://midena.gov.ec/content/view/1261/208/
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://naviny.by/rubrics/society/2011/09/16/ic_articles_116_175144/
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://news.mail.ru/politics/6861560/
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://news.sinhalaya.com/wmview.php?ArtID=11002
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://news.tut.by/society/250578.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://newspot.byegm.gov.tr/arsiv/1996/21/N4.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://noticias.terra.com.br/brasil/noticias/0
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://palvoice.org/forums/showthread.php?t=245697
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/DEC3592.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/Dec3630.jpg
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/Dec3632.jpg
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/DecHV.h$#
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/DecHV.html
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/DecHV5539.gif
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/DecHV5920.gif
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/DecHV6212.gif
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/DecHV99.gif
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/Fusbr.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/Fusbrhv.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HISTHV.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV1252.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV1636.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV1674.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV1991.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV1992.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV2000.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV20466.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV21896.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV23195.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV27496.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV27998.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV32308.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV34724.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV52700.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV53071.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV53604.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV55639.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV57303.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV57843.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV63429.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV91698.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV942.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV94922.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV96676.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV98077.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/HV99530.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/figuras/HV2495.JPG
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/figuras/HV3150.gif
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/figuras/HV3916.gif
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/figuras/Hv98.jpg
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://pcdsh01.on.br/verao1.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://petra.gov.jo/Artical.aspx?Lng=2&Section=8&Artical=95279
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://portal.rada.gov.ua/rada/control/en/publish/article/info_left?art_id=287324&cat_id=105995
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://rega.basbakanlik.gov.tr/eskiler/2007/03/20070307-7.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ru.publika.md/link_317061.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://sana.sy/ara/2/2008/10/07/195459.htm
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://sns.sy/sns/?path=news/read/11421
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://star.arabia.com/990701/JO9.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://star.arabia.com/990930/JO9.html
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://story.philippinetimes.com/p.x/ct/9/id/145be20cc6b121c0/cid/3e5bbccc730d258c/
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://student.cusu.cam.ac.uk/~jsm28/british-time/
Source: GeoSetter.exe, 00000007.00000003.2485959928.0000000009620000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://student.cusu.cam.ac.uk/~jsm28/british-time/bbc-19410418.png
Source: GeoSetter.exe, 00000007.00000003.2485959928.0000000009620000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://student.cusu.cam.ac.uk/~jsm28/british-time/ho-19410421.
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://student.cusu.cam.ac.uk/~jsm28/british-time/ho-19410421.png
Source: GeoSetter.exe, 00000007.00000003.2485959928.0000000009620000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://student.cusu.cam.ac.uk/~jsm28/british-timeT
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://thawra.alwehda.gov.sy/_View_news2.asp?FileName=94459258720090318012209
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://tile.stamen.com/terrain-background
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://tile.stamen.com/terrain-backgroundSVW
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://today.reuters.co.uk/news/newsArticle.aspx?type=scienceNews&storyID=2006-04-12T172228Z_01_COL2
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://toi.iriti.cnr.it/uk/ienitlt.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://trip.rk.ee/cgi-bin/thw?$
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://ubpost.mongolnews.mn/index.php?subaction=showcomments&id=1111634894&archive=&start_from=&ucat
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095C8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483542296.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://uk.reuters.com/article/oilRpt/idUKBLA65048420070916
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://w1.c1.rada.gov.ua/pls/zweb_n/webproc4_1?id=&pf3511=41484
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://wehda.alwehda.gov.sy/_print_veiw.asp?FileName=12521710520070926111247
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://ws.geonames.net
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://ws.geonames.net/viewAccount?username=%s&token=%s
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://ws.geonames.net/viewAccount?username=%s&token=%sSV
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.abc.com.pl/serwis/mp/1995/0162.hp)
Source: GeoSetter.exe, 00000007.00000003.2485048789.0000000009610000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.abc.com.pl/serwis/mp/1995/0162.htm
Source: GeoSetter.exe, 00000007.00000003.2483666998.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.abcnews.go.com/International/wireStory?id=56760
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.abcnews.go.com/International/wireStory?id=5676087
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483607874.0000000009604000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.aljeeran.net/wesima_articles/news-20080305-98602.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.allmoldova.com/moldova-news/1249064116.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.alomaliye.com/bkk_2002_3769.htm
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.apakistannews.com/govt-withdraws-plan-to-advance-clocks-172041
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.apakistannews.com/govt-withdraws-plan-to-advance-clocks-172T6
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.app.com.pk/en_/index.php?option=com_content&task=view&id=73043&Itemid=
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.app.com.pk/en_/index.php?option=com_content&task=view&id=73043&Itemid=1
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.app.com.pk/en_/index.php?option=com_content&task=view&id=73043&Itemid=1P%
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.app.com.pk/en_/index.php?option=com_content&task=view&id=86715&Itemid=
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.app.com.pk/en_/index.php?option=com_content&task=view&id=86715&Itemid=2
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.app.com.pk/en_/index.php?option=com_content&task=view&id=86715&Itemid=2x
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.app.com.pk/en_/index.php?option=com_content&task=view&id=99374&Itemid=
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.app.com.pk/en_/index.php?option=com_content&task=view&id=99374&Itemid=2
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.arabtimesonline.com/arabtimes/kuwait/Viewdet.asp?ID=9950
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.argentina.gob.ar/argentina/portal/paginas.dhtml?pagina=356
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.asiantribune.com/?q=node/17288
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.astro.com/atlas
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.astro.uni.torun.pl/~kb/Artykuly/U-PA/Czas2.htm#tth_tAb
Source: GeoSetter.exe, 00000007.00000003.2485048789.0000000009610000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.astro.uni.torun.pl/~kb/Artykuly/U-PA/Czas2.htm#tth_tAb1
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483607874.0000000009604000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.aswataliraq.info/look/article.tpl?id=2047&IdLanguage=17&IdPublication=4&NrArticle=71743&N
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.baltictimes.com/
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.bartleby.com/65/sv/Svalbard.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.belta.by/ru/all_news/society/V-Belarusi-otmenjaetsja-perexod-na-sezonnoe-vremja_i_572952.
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.boletinoficial.gov.ar/Bora.Portal/CustomControls/PdfContent.aspx?fp=16102008&pi=3&pf=4&s=
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.boletinoficial.gov.ar/Bora.Portal/CustomControls/PdfContent.aspx?fp=17102008&pi=1&pf=1&s=
Source: GeoSetter.exe, 00000007.00000003.2484745468.0000000009620000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.bom.gov.au/climate/averages/tables/dst_times.shtml
Source: GeoSetter.exe, 00000007.00000003.2484745468.0000000009620000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.bom.gov.au/faq/faqgen.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.byegm.gov.tr/YAYINLARIMIZ/CHR/ING2000/03/00X03X06.HTM#%2021
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.byegm.gov.tr/YAYINLARIMIZ/CHR/ING2001/03/23x03x01.HTM#%2027
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.byegm.gov.tr/YAYINLARIMIZ/CHR/ING97/03/97X03X25.TXT
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.byegm.gov.tr/YAYINLARIMIZ/CHR/ING98/03/98X03X02.HTM
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.byegm.gov.tr/YAYINLARIMIZ/CHR/ING99/10/99X10X26.HTM#%2016
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.canadiangeographic.ca/Magazine/SO98/geomap.
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.cddhcu.gob.mx/bibliot/publica/inveyana/polisoc/horver/(
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.clarin.com.ar/diario/2001-06-22/s-03601.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.clarin.com.ar/diario/2001-06-22/s-03601.htmV
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095C8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.cwb.gov.tw/V6/astronomy/cdata/summert.h
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095C8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.cwb.gov.tw/V6/astronomy/cdata/summert.htm
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dailytimes.com.pk/default.asp?page=2008%5C05%5C15%5Cstory_15-5-2008_pg1
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dailytimes.com.pk/default.asp?page=2008%5C05%5C15%5Cstory_15-5-2008_pg1_4
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dawn.com/2002/10/06/top13.htm
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dawn.com/2003/03/07/top15.T
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dawn.com/2003/03/07/top15.htm
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.delphizip.org
Source: GeoSetter.exe, 00000007.00000003.2485959928.0000000009620000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dhm.de/lemo/html/biografien/BersarinNikolai/
Source: GeoSetter.exe, 00000007.00000003.2484591039.0000000009613000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dia.govt.nz/diawebsite.nsf/wpg_URL/Services-Daylight-Saving-Daylight-saving-to-be-exten
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.diariocolatino.com/internacionales/detalles.asp?NewsID=8079
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.diarionoticias.com.py/011000/nacional/naciona1.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.diputadossanluis.gov.ar/diputadosasp/paginas/verNorma.asp?NormaID=276
Source: geosetter_setup.tmp, 00000001.00000003.2459216915.00000000021E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dk-soft.org/
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dlapr.lib.az.us/links/daylight.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.eldiariodelarepublica.com/index.php?option=com_content&task=view&id=29383&Itemid=9
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.elnuevodiario.com.ni/2006/05/01/nacionales/1841
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.elta.lt/
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.emol.com/noticias/nacional/detalle/detallenoticias.asp?idnoticia=467651
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.eznis.com/Container.jsp?id=
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.eznis.com/Container.jsp?id=112
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2487531261.0000000009612000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.falklandnews.com/public/story.cfm?get=5914&source=3
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.famfamfam.com
Source: GeoSetter.exe, 00000007.00000003.2484745468.0000000009620000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.fiji.gov.fj/index.php?option=com_content&view=article&id=1096:3310-cabinet-approves-chang
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.fjysgl.gov.cn/show.aspx?id=2379&cid
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.fjysgl.gov.cn/show.aspx?id=2379&cid=39
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.fjysgl.gov.cn/show.aspx?id=2379&cid=39t
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.friedemann-schmidt.com/geosetter/gmap21.html
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geonames.org
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geonames.org/account
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geonames.org/login
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geonames.org/services.html
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp, GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geosetter.de
Source: geosetter_setup.exe, 00000000.00000003.2053065082.00000000020A4000.00000004.00001000.00020000.00000000.sdmp, geosetter_setup.exe, 00000000.00000003.2461969425.00000000020B0000.00000004.00001000.00020000.00000000.sdmp, geosetter_setup.tmp, 00000001.00000003.2054977128.00000000021CC000.00000004.00001000.00020000.00000000.sdmp, geosetter_setup.tmp, 00000001.00000003.2458860762.00000000021D4000.00000004.00001000.00020000.00000000.sdmp, geosetter_setup.tmp, 00000001.00000003.2459808738.00000000021D8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.geosetter.de&
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geosetter.de/donation-de/
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geosetter.de/donation-de/openhttp://www.geosetter.de/en/donation-en/S
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geosetter.de/en/donation-en/
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geosetter.de/geosetter_beta.exeU
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geosetter.de/languages/
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geosetter.de4http://www.geosetter.de/en
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geosetter.deDhttp://www.geosetter.de/changes-de4http://www.geosetter.de/enJhttp://www.geo
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.geosetter.deTPF0
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.globovision.com/news.php?nid=72208
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.gobernac.mendoza.gov.ar/boletin/pdf/20040521-27158-normas.pdf
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.gobernac.mendoza.gov.ar/boletin/pdf/20040924-27244-normas.pdf
Source: GeoSetter.exe, 00000007.00000003.2487461434.00000000095F3000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.gobiernodechile.cl/viewNoticia.aspx?idArticulo=3009
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.gobiernodechile.cl/viewNoticia.aspx?idArticulo=30098
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.google.com/kml/ext/2.2
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.gov.mu/portal/goc/assemblysite/file/bill2708.pd
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2482907104.00000000095C8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.gov.mu/portal/goc/assemblysite/file/bill2708.pdf
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2482907104.00000000095C8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.gov.mu/portal/site/pmosite/menuitem.4ca0efdee47462e7440a600248a521ca/?content_id=4728ca68
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.gov.on.ca/MBS/english/publications/statregs/conttext.html
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.gov.yk.ca/legislation/regs/oic1987_056.0
Source: GeoSetter.exe, 00000007.00000003.2485171150.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486091069.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.government.ru/content/governmentactivity/rfgovernmentdecisions/archiv
Source: GeoSetter.exe, 00000007.00000003.2485171150.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486091069.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.government.ru/content/governmentactivity/rfgovernmentdecisions/archive/2009/09/14/991633.
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.gpsbabel.org
Source: GeoSetter.exe, 00000007.00000003.2486867873.0000000009610000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.granma.cu/espanol/2005/noviembre/mier9/horario.html
Source: GeoSetter.exe, 00000007.00000003.2486867873.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.granma.cu/ingles/2004/septiembre/juev30/41medid-i.h
Source: GeoSetter.exe, 00000007.00000003.2486867873.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.granma.cu/ingles/2006/octubre/lun16/43horario.h
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.granma.cubaweb.cu/2007/10/24/nacional/artic07.h
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.granma.cubaweb.cu/english/news/art89.html
Source: GeoSetter.exe, 00000007.00000003.2483666998.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.guardian.co.uk/world/feedarticle/775900
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.guardian.co.uk/world/feedarticle/7759001
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hko.gov.hk/gts/time/Summertime.
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hko.gov.hk/gts/time/Summertime.htm
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hko.gov.hk/gts/time/Summertime.htmH
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hko.gov.hk/gts/time/Summertime.htmH7
Source: GeoSetter.exe, 00000007.00000003.2487461434.00000000095F3000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.horaoficial.cl/cambio.h
Source: GeoSetter.exe, 00000007.00000003.2487461434.00000000095F3000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.horaoficial.cl/cambio.hP
Source: GeoSetter.exe, 00000007.00000003.2487461434.00000000095F3000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.horaoficial.cl/cambio.hp
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.horaoficial.cl/cambio.htm
Source: GeoSetter.exe, 00000007.00000003.2487461434.00000000095F3000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.horaoficial.cl/horaof.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hoy.com.ec/NoticiaNue.asp?row_id=249856
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095C8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hri.org/news/world/undh/last/00-08-16.undh.htmD
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hri.org/news/world/undh/last/00-08-16.undh.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hum.aau.dk/~poe/tid/tine/DanskTid.htm
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hup.harvard.edu/catalog/HEISUN.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.hurriyet.com.tr/ekonomi/17230464.asp?gid=373
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.iht.com/articles/ap/2007/03/29/africa/ME-GEN-Syria-Time-Change.php
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.in.gov.br/visualiza/index.jsp?data=13/10/2011&jornal=1000&pagina=6&totalArquivos=6
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.in.gov.br/visualiza/index.jsp?data=13/10/2011&jornal=1000&pagina=6&totalArquivos=60
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.indyproject.org/
Source: geosetter_setup.tmp, geosetter_setup.tmp, 00000001.00000000.2054211311.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: http://www.innosetup.com/
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.irishstatutebook.ie/ZZA13Y1923.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095C8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483542296.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.irna.ir/en/news/view/line-17/0603193812164948.h
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.irna.ir/en/news/view/line-17/0603193812164948.htm
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483607874.0000000009604000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.japantimes.co.jp/cgi-bin/getarticle.pl5?nn20050810f2.htm
Source: GeoSetter.exe, 00000007.00000003.2486867873.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.jonesbahamas.com/?c=45&a=10
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.jpost.com/MiddleEast/Article.aspx?id=235650
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.jpost.com/com/Archive/22.Apr.1999/Opinion/Article-2.html
Source: geosetter_setup.exe, geosetter_setup.exe, 00000000.00000002.2462074891.0000000000401000.00000020.00000001.01000000.00000003.sdmp String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline
Source: geosetter_setup.exe, 00000000.00000002.2462074891.0000000000401000.00000020.00000001.01000000.00000003.sdmp String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.jrsoftware.org/isinfo.php
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.jujuy.gov.ar/index2/partes_prensa/18_10_08/235-181008.doc
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.kazsociety.org.uk/news/2005/03/30.htm
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483607874.0000000009604000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.koreaherald.co.kr/SITE/data/html_dir/2006/07/10/200607100012.asp
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.kyivpost.ua/russia/news/pridnestrove-otkazalos-ot-perehoda-na-zimnee-vremya-30954.html
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lagaceta.com.ar/vernotae.asp?id_nota=253414
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lanacion.com.ar/04/05/27/de_604825.asp
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lanacion.com.ar/04/05/28/de_605203.asp
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lanacion.com.ar/04/06/10/de_609078.asp
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lanacion.com.ar/nota.asp?nota_id=1107912
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lapalmainteractivo.com/guias/content/gen/ap/America_Latina/AMC_GEN_NICARAGUA_HORA.h
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2482907104.00000000095C8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lexpress.mu/display_article.php?news_id=111216
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lexpress.mu/display_article.php?news_id=111X
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.locr.com
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.locr.com/api
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.locr.com/photo/album/albums.php?album_id=%s
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.locr.com/user/my_page/my_photos_edit.php
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.locr.com/user/my_page/my_photos_edit.phpopen
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.locr.com/user_create.php
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.locr.comTPF0
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lovdata.no/all/nl-18940629-001.html
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lovdata.no/all/nl-19250717-011.html
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lovdata.no/all/nl-19300227-002.html).
Source: GeoSetter.exe, 00000007.00000003.2485959928.0000000009620000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lrvk.lt/nut/11/n1749.ht
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lrvk.lt/nut/11/n1749.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.lv-laiks.lv/wwwraksti/2000/071072/vd4.htm
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.maannews.net/eng/ViewDetails.aspx?ID=271178
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.maannews.net/eng/ViewDetails.aspx?ID=306795
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.maannews.net/eng/ViewDetails.aspx?ID=416217
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.maannews.net/eng/ViewDetails.aspx?ID=424808
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.madshi.net
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.manilastandardtoday.com/?page=politics02_april26_2006
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.math.nus.edu.sg/aslaksen/teaching/timezone.html
Source: GeoSetter.exe, 00000007.00000003.2484745468.0000000009620000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mcil.gov.ws/mcil_publications.h
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mme.gov.br/firs
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mme.gov.br/first
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mme.gov.br/site/news/detail.do;jsessionid=BBA06811AFCAAC28F0285210913513DA?newsId=13975
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mme.gov.br/site/news/detail.do;jsessionid=BBA06811AFCAAC28F0285210913513DA?newsId=139750
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mme.gov.br/site/news/detail.do?newsId=1672
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mme.gov.br/site/news/detail.do?newsId=16722
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.moi.gov.ps/en/?page=633167343250594025&nid=11505
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mongoliatourism.gov.mn/general.htm
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mongolnews.mn/index.php?module=unuudur&sec=view&id=1574$
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.mongolnews.mn/index.php?module=unuudur&sec=view&id=15742
Source: GeoSetter.exe, 00000007.00000003.2484745468.0000000009620000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.morningstar.co.uk/uk/markets/newsfeeditem.aspx?id=1385019583479
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.mustangpeak.net
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.mytopo.com
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.news.lk/
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.nineoclock.ro/POL/1778pol.html
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.nnc.cubaweb.cu/marzo-2008/cien-1-11-3-08.ht
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.nnc.cubaweb.cu/marzo-2008/cien-1-11-3-08.htm
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.nnsl.com/frames/newspapers/2006-11/nov13_06none.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ntvmsnbc.com/news/402029.asp
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.nunatsiaq.com/archives/nunavut001130/nvt21110_02.html
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.nunatsiaq.com/archives/nunavut991130/nvt91119_17.html
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.nunatsiaq.com/nunavut/nvt10309_06.html
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.nunatsiaq.com/nunavut/nvt90903_13.html
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.nunavut.com/basicfacts/english/basicfacts_1territory.html
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.openstreetmap.org
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.pak.gov.pk/public/news/app/app06_dec.htm
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.pak.gov.pk/public/news/app/app06_dec.htp
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.parlament-berlin.de/pds-fraktion.nsf/727459127c8b66ee8525662300459099/defc77cb784f180ac12
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.parliament.the-stationery-office.co.uk/pa/ld199697/ldhansrd/pdvn/lds97/text/70611-20.htm#
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.petranews.gov.jo/nepras/2006/Sep/05/4000.htm
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.petranews.gov.jo/nepras/2006/Sep/05/4000.htmN
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.pettswoodvillage.co.uk/Daylight_Savings_William_Willett.pdf
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.phys.uu.nl/~vgent/idl/idl.htm
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.phys.uu.nl/~vgent/wettijd/wettijd.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.planalto.gov.br/ccivil_03/_Ato2004-2006/2004/Decreto/D5223.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.planalto.gov.br/ccivil_03/_Ato2007-2010/2008/Decreto/D6558.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.pravda.com.ua/rus/news/2011/09/20/6600616/
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.prensalatina.com.mx/article.asp?ID=%7B4CC32C1B-A9F7-42FB-8A07-8631AFC923AF%7D&language=D)
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gob.ni/Presidencia/Files_index/Secretaria/Notas%20de%20Prensa/Presidente/2005
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gob.ni/buscador_gaceta/BD/DECRETOS/2005/Decreto%2023-2005%20Se%20adelanta%20e
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gob.ni/presidencia/files_index/secretaria/comunicados/2005/septiembre/26septi
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gov.br/CCIVIL/decreto/2002/D4399.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gov.br/CCIVIL/decreto/2003/D4844.htm
Source: GeoSetter.exe, 00000007.00000003.2487461434.00000000095F0000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gov.py/decretos/D1867.pdf
Source: GeoSetter.exe, 00000007.00000003.2487461434.00000000095F0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gov.py/v1/wp-content/uploads/2010/02/decreto3958.pd
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gov.py/v1/wp-content/uploads/2010/02/decreto3958.pdf
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gub.uy/_Web/decretos/2005/09/CM%20119_09%2009%202005_00001.PDF
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gub.uy/_Web/noticias/2005/03/2005031005.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gub.uy/_web/decretos/2006/09/CM%20210_08%2006%202006_00001.PDF
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.presidencia.gub.uy/decretos/2004091502.htm
Source: GeoSetter.exe, 00000007.00000003.2485959928.0000000009620000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ptb.de/de/org/4/44/441/salt.htm
Source: GeoSetter.exe, 00000007.00000003.2486867873.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.qp.gov.sk.ca/documents/English/Statutes/Statutes/T14.pd
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.radiohc.cu/espanol/noticias/mar07/11mar/hor.htD2
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.radiohc.cu/espanol/noticias/mar07/11mar/hor.htD2O
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.radiohc.cu/espanol/noticias/mar07/11mar/hor.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.regnum.ru/news/polit/1413906.html
Source: geosetter_setup.exe, 00000000.00000003.2053379279.0000000002470000.00000004.00001000.00020000.00000000.sdmp, geosetter_setup.exe, 00000000.00000003.2053568971.00000000020EC000.00000004.00001000.00020000.00000000.sdmp, geosetter_setup.tmp, geosetter_setup.tmp, 00000001.00000000.2054211311.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: http://www.remobjects.com/ps
Source: geosetter_setup.exe, 00000000.00000003.2053379279.0000000002470000.00000004.00001000.00020000.00000000.sdmp, geosetter_setup.exe, 00000000.00000003.2053568971.00000000020EC000.00000004.00001000.00020000.00000000.sdmp, geosetter_setup.tmp, 00000001.00000000.2054211311.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: http://www.remobjects.com/psU
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.retsinfo.dk/_GETDOCI_/ACCN/A18930008330-REGL
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.retsinfo.dk/_GETDOCI_/ACCN/A19722110030-REGL
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.retsinfo.dk/_GETDOCI_/ACCN/A19740022330-REGL
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.retsinfo.dk/_GETDOCI_/ACCN/C19801120554-REGL
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.rferl.org/newsline/2001/01/3-CEE/cee-030101.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.riksdagen.se/english/work/sfst.asp
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.safa.ps/ara/?action=showdetail&seid=4158
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sana.sy/ara/2/2009/09/29/247012.htm
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sana.sy/eng/21/2008/03/11/165173.htm
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sana.sy/eng/21/2008/03/11/165173.htmZ
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sana.sy/eng/21/2009/03/17/217563.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sanjuan.gov.ar/prensa/archivo/000329.html
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sanjuan.gov.ar/prensa/archivo/000426.html
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sanjuan.gov.ar/prensa/archivo/000441.html
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sanluis.gov.ar
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sanluis.gov.ar/SL/Paginas/NoticiaDetalle.asp?TemaId=1&InfoPrensaId=3102
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sanluis.gov.ar/notas.asp?idCanal=0&id=22812
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sanluis.gov.ar/notas.asp?idCanal=8141&id=22834
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.segodnya.ua/news/14290482.html
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.senat.gov.pl/k5/dok/sejm/053/2180.pdf
Source: GeoSetter.exe, 00000007.00000003.2487461434.00000000095F3000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.shoa.cl/noticias/2008/04hora/hora.hp
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.shoa.cl/noticias/2008/04hora/hora.htm
Source: GeoSetter.exe, 00000007.00000003.2487461434.00000000095F3000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.shoa.cl/servicios/supremo316.pd
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.shoa.cl/servicios/supremo316.pdf
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.shrine.org.
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sieca.org.gt/Sitio_publico/Energeticos/Doc/Medidas/Cambio_Horario_Nac_190406.pdf
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.smh.com.au/news/9905/26/pageone/pageone4.html
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.sno.phy.queensu.ca/~phil/exiftool/
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.spicasc.net/horvera.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.statkart.no/efs/efshefter/2001/efs5-2001.pdf
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095C8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sumatera-inc.com/go_to_invest/about_indonesia.asp#standtim
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.sumatera-inc.com/go_to_invest/about_indonesia.asp#standtime
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.svalbard.com/SvalbardFAQ.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thaindian.com/newsportal/business/bangladesh-to-continue-indefinitely-with-advanced-time_
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.thany.org/
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.theage.com.au/news/national/daylight-savings-to-span-six-months/2007/06/27/1182623966703.
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thedailystar.net/newDesign/latest_news.php?nid=2281
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thedailystar.net/newDesign/latest_news.php?nid=22817
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thedailystar.net/newDesign/news-details.php?nid=107021
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thedailystar.net/newDesign/news-details.php?nid=107P
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thedailystar.net/newDesign/news-details.php?nid=107P_M#
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thedailystar.net/newDesign/news-details.php?nid=119228
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thedailystar.net/newDesign/news-details.php?nid=119P
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thelaw.tas.gov.au/fragview/42
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thenews.com.pk/daily_detail.asp?id=17120#
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thenews.com.pk/daily_detail.asp?id=171280
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thenews.com.pk/top_story_detail.asp?Id=2474
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thenews.com.pk/top_story_detail.asp?Id=24742
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thenews.com.pk/updates.asp?id=8716
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thenews.com.pk/updates.asp?id=87168
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.thenews.com.pk/updates.asp?id=87168L)
Source: GeoSetter.exe, 00000007.00000003.2486867873.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.theroyalgazette.com/apps/pbcs.dll/article?AID=/20060529/NEWS/105290P0
Source: GeoSetter.exe, 00000007.00000003.2486867873.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.theroyalgazette.com/apps/pbcs.dll/article?AID=/20060529/NEWS/105290P0;(#
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/bangladesh-daylight-saving-2009.h
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/bangladesh-daylight-saving-2009.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/bangladesh-daylight-saving-2009.htmld
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/brazil-dst-2008-2009.htm
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/brazil-dst-2008-2009.html
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/cuba-starts-dst-march-16.html
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/cuba-starts-dst-march-16.htmt/
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/cuba-starts-dst-march-16.htmt/WD#
Source: GeoSetter.exe, 00000007.00000003.2484745468.0000000009620000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/fiji-dst-ends-march-2010.htm
Source: GeoSetter.exe, 00000007.00000003.2484745468.0000000009620000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/fiji-dst-ends-march-2010.html
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483607874.0000000009604000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/iraq-dumps-daylight-saving.html
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/pakistan-ends-dst09.h
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/pakistan-ends-dst09.html
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/palestine-dst-2011.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/syria-dst-starts-march-27-2009.html
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/westbank-gaza-dst-2009.html
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/news/time/westbank-gaza-end-dst-2010.html
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/worldclock/city.html?n=102
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/worldclock/city.html?n=1026
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/worldclock/timezone.html?n=107
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/worldclock/timezone.html?n=11
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.timeanddate.com/worldclock/timezone.html?n=116
Source: GeoSetter.exe, 00000007.00000003.2484591039.000000000960C000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2484059778.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.tongatapu.net.to/tonga/homeland/timebegins.htm
Source: GeoSetter.exe, 00000007.00000003.2485959928.0000000009620000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.tourism.lt/informa/ff.htm
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486362486.0000000009648000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.turksandcaicos.tc/calendar/index.htm
Source: GeoSetter.exe, 00000007.00000003.2486000379.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ucalgary.ca/UofC/departments/UP/1-55238/1-55238-110-2.html
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.uphere.ca/node/4938R
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.uphere.ca/node/4938R/
Source: GeoSetter.exe, 00000007.00000003.2486841143.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.uphere.ca/node/dR
Source: GeoSetter.exe, 00000007.00000003.2485959928.0000000009620000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.winstonchurchill.org/fh114willett.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldbulletin.net/?aType=haber&ArticleID=70872
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimeserver.com/current_time_in_MN.aspL
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimeserver.com/current_time_in_MN.aspx
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.c.
Source: GeoSetter.exe, 00000007.00000003.2487377772.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/brazil-time-new-old.p
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/brazil-time-new-old.php
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_argentina08.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_bangladesh02.htP
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_bangladesh02.htP_L#
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_bangladesh02.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_bangladesh04.ht
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_bangladesh04.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_bangladesh05.ht$
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_bangladesh05.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_bangladesh06.ht
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_bangladesh06.html
Source: GeoSetter.exe, 00000007.00000003.2486925654.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_cuba03.html8
Source: GeoSetter.exe, 00000007.00000003.2483666998.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_gazastrip01.htm
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_gazastrip01.html
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_gazastrip02.html
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_gazastrip05.html
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_mauritius02.htm
Source: GeoSetter.exe, 00000007.00000003.2483444097.00000000095D0000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2482907104.00000000095C8000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_mauritius02.html
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_pakistan02.htm
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_pakistan02.html
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_pakistan05.htm
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_pakistan05.html
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_pakistan07.D
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_pakistan07.htm
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486091069.00000000095EC000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_russia03.html
Source: GeoSetter.exe, 00000007.00000003.2483666998.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_westbank01.htmX3
Source: GeoSetter.exe, 00000007.00000003.2483666998.000000000960C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_westbank01.htmX3K9#
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_westbank01.html
Source: GeoSetter.exe, 00000007.00000003.2483199614.00000000095E8000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483123371.000000000961C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.com/dst_news/dst_news_westbank03.html
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.net/dst_news/dst_news_argentina02.html
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.net/dst_news/dst_news_pakistan01.htm
Source: GeoSetter.exe, 00000007.00000003.2483691540.0000000009614000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2483058159.0000000009610000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.worldtimezone.net/dst_news/dst_news_pakistan01.html
Source: GeoSetter.exe, 00000007.00000003.2485467240.0000000009628000.00000004.00001000.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2486117127.00000000095CE000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.yle.fi/elavaarkisto/?s=s&g=1&ag=5&t=&a=3401
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp, GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.zoomin.de
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.zoomin.de/hilfe/spezielle-funktionen/geosetter/
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.zoomin.de/hilfe/spezielle-funktionen/geosetter/openU
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.zoomin.de/registrieren
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.zoomin.deopen
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www.zoomin.deopenU
Source: GeoSetter.exe, 00000007.00000000.2455770204.0000000000D10000.00000002.00000001.01000000.0000000B.sdmp String found in binary or memory: http://www2.jpl.nasa.gov/srtm/
Source: GeoSetter.exe, 00000007.00000003.2517124090.0000000008D6F000.00000004.00000020.00020000.00000000.sdmp, GeoSetter.exe, 00000007.00000003.2549685981.000000000A5D9000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://leafletjs.com
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://owl.phy.queensu.ca/~phil/exiftool/rss.xml
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/proxytest.dat
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/proxytest.datU
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/languages/
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/languages/versions
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/version
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/version_beta
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/version_beta_release_date
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/version_locr
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/version_locr_release_date
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/version_release_date
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/version_release_dateU
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/version_zoomin
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp String found in binary or memory: https://www.geosetter.de/update/version_zoomin_release_date
Source: GeoSetter.exe, 00000007.00000003.2486990828.0000000009630000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.in.gov.br/imprensa/visualiza/index.jsp?jornal=do&secao=1&pagina=1&data=25/04/2008
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49980
Source: unknown Network traffic detected: HTTP traffic on port 49980 -> 443
Source: unknown HTTPS traffic detected: 130.15.24.27:443 -> 192.168.2.5:49980 version: TLS 1.2
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process Stats: CPU usage > 49%
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00423FD4 NtdllDefWindowProc_A, 1_2_00423FD4
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00412A28 NtdllDefWindowProc_A, 1_2_00412A28
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0042F9C0 NtdllDefWindowProc_A, 1_2_0042F9C0
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00479D08 NtdllDefWindowProc_A, 1_2_00479D08
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00457D90 PostMessageA,PostMessageA,SetForegroundWindow,NtdllDefWindowProc_A, 1_2_00457D90
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0042ED84: CreateFileA,DeviceIoControl,GetLastError,CloseHandle,SetLastError, 1_2_0042ED84
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_004098E8 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_004098E8
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00455D80 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 1_2_00455D80
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_00408888 0_2_00408888
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00468034 1_2_00468034
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00471688 1_2_00471688
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00488030 1_2_00488030
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0046A088 1_2_0046A088
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00452100 1_2_00452100
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0043E1F0 1_2_0043E1F0
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004307FC 1_2_004307FC
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00444968 1_2_00444968
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00434A64 1_2_00434A64
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00444F10 1_2_00444F10
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00488F90 1_2_00488F90
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00431388 1_2_00431388
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00445608 1_2_00445608
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0048F6BC 1_2_0048F6BC
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00435768 1_2_00435768
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0045F8C0 1_2_0045F8C0
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0045B970 1_2_0045B970
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00445A14 1_2_00445A14
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Code function: 9_2_00402C00 9_2_00402C00
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Code function: 9_2_00401560 9_2_00401560
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_00404580 15_2_00404580
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_62D841C0 15_2_62D841C0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_62D89890 15_2_62D89890
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_62D84DAC 15_2_62D84DAC
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_65601B39 15_2_65601B39
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_66A0E690 15_2_66A0E690
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_66A014C0 15_2_66A014C0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_66A100D9 15_2_66A100D9
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_66A0F868 15_2_66A0F868
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_66A0D475 15_2_66A0D475
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_66A0A5C0 15_2_66A0A5C0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_66A06F21 15_2_66A06F21
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAEEDC0 15_2_6DAEEDC0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBAAD50 15_2_6DBAAD50
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB86CF2 15_2_6DB86CF2
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAF4CF0 15_2_6DAF4CF0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DACAC25 15_2_6DACAC25
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAF2C6B 15_2_6DAF2C6B
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DADAC7B 15_2_6DADAC7B
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB14F89 15_2_6DB14F89
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC0CF20 15_2_6DC0CF20
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC1CF30 15_2_6DC1CF30
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE6F5C 15_2_6DAE6F5C
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE2E70 15_2_6DAE2E70
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB8A91D 15_2_6DB8A91D
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB148B3 15_2_6DB148B3
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBBE870 15_2_6DBBE870
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBC2BA0 15_2_6DBC2BA0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBBCBE0 15_2_6DBBCBE0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE6B20 15_2_6DAE6B20
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAF2AB3 15_2_6DAF2AB3
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB04A95 15_2_6DB04A95
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBCC5A0 15_2_6DBCC5A0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBC2590 15_2_6DBC2590
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB1452B 15_2_6DB1452B
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAF849C 15_2_6DAF849C
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB7C4F0 15_2_6DB7C4F0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAFE4E0 15_2_6DAFE4E0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAF24FA 15_2_6DAF24FA
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC164B0 15_2_6DC164B0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC12460 15_2_6DC12460
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB9A41B 15_2_6DB9A41B
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB3C36C 15_2_6DB3C36C
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAF8693 15_2_6DAF8693
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAEC1D1 15_2_6DAEC1D1
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBCA130 15_2_6DBCA130
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB2C120 15_2_6DB2C120
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB0A100 15_2_6DB0A100
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE8140 15_2_6DAE8140
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB58142 15_2_6DB58142
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB3E0BC 15_2_6DB3E0BC
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBBE3C0 15_2_6DBBE3C0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB3C36C 15_2_6DB3C36C
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBAC340 15_2_6DBAC340
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE42EC 15_2_6DAE42EC
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB082E0 15_2_6DB082E0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB32260 15_2_6DB32260
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB68260 15_2_6DB68260
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB3824C 15_2_6DB3824C
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB2FC99 15_2_6DB2FC99
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB0BCD0 15_2_6DB0BCD0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBC5C00 15_2_6DBC5C00
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAEBF23 15_2_6DAEBF23
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB43EF0 15_2_6DB43EF0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAEBE30 15_2_6DAEBE30
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE5921 15_2_6DAE5921
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE794C 15_2_6DAE794C
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE5952 15_2_6DAE5952
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE58BF 15_2_6DAE58BF
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE588E 15_2_6DAE588E
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAC98EC 15_2_6DAC98EC
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB518F0 15_2_6DB518F0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE58F0 15_2_6DAE58F0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBAF870 15_2_6DBAF870
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC13810 15_2_6DC13810
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE585D 15_2_6DAE585D
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB37B80 15_2_6DB37B80
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE9A90 15_2_6DAE9A90
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB43A50 15_2_6DB43A50
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAEF4BC 15_2_6DAEF4BC
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE74D0 15_2_6DAE74D0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE57AA 15_2_6DAE57AA
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAE57E9 15_2_6DAE57E9
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB3D7FA 15_2_6DB3D7FA
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB577C9 15_2_6DB577C9
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBB56F0 15_2_6DBB56F0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB35630 15_2_6DB35630
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB99600 15_2_6DB99600
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DACB18E 15_2_6DACB18E
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC25099 15_2_6DC25099
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DAFB0D8 15_2_6DAFB0D8
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC1D060 15_2_6DC1D060
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DB57069 15_2_6DB57069
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DBCD050 15_2_6DBCD050
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC152C0 15_2_6DC152C0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DACD22B 15_2_6DACD22B
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 00446274 appears 45 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 0040596C appears 114 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 00453AAC appears 97 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 0043497C appears 32 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 00458718 appears 79 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 00403400 appears 62 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 0040905C appears 45 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 00407D44 appears 43 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 00446544 appears 58 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 0045850C appears 100 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 00403494 appears 84 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 0040357C appears 33 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 00406F14 appears 45 times
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: String function: 00403684 appears 229 times
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: String function: 6DC137D0 appears 35 times
Source: geosetter_setup.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: geosetter_setup.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: geosetter_setup.tmp.0.dr Static PE information: Resource name: RT_VERSION type: 370 sysV pure executable not stripped
Source: is-1BDNO.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-1BDNO.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-1BDNO.tmp.1.dr Static PE information: Resource name: RT_VERSION type: 370 sysV pure executable not stripped
Source: is-07QKO.tmp.1.dr Static PE information: Resource name: RT_STRING type: PDP-11 separate I&D executable not stripped
Source: is-5LPT9.tmp.1.dr Static PE information: Number of sections : 14 > 10
Source: is-LEN5V.tmp.1.dr Static PE information: Number of sections : 11 > 10
Source: geosetter_setup.exe, 00000000.00000003.2053379279.0000000002470000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs geosetter_setup.exe
Source: geosetter_setup.exe, 00000000.00000003.2053568971.00000000020EC000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs geosetter_setup.exe
Source: geosetter_setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engine Classification label: sus24.evad.winEXE@26/1166@2/2
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC0E060 win32_str_os_error,FormatMessageA,LocalAlloc,GetLastError,sprintf,Perl_get_context,Perl_sv_setpvn,LocalFree, 15_2_6DC0E060
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_004098E8 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_004098E8
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00455D80 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 1_2_00455D80
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_70843DEC Perl_sv_2pv_flags,GetCurrentProcess,OpenProcessToken,AdjustTokenPrivileges,LookupPrivilegeValueA,AdjustTokenPrivileges,AbortSystemShutdownA,AdjustTokenPrivileges,CloseHandle,Perl_newSViv,Perl_sv_2mortal,Perl_croak_nocontext,Perl_sv_2pv_flags,GetCurrentProcess,OpenProcessToken,Perl_sv_2pv_flags,Perl_sv_2iv_flags,Perl_sv_2iv_flags,Perl_sv_2iv_flags,InitiateSystemShutdownA,AdjustTokenPrivileges,CloseHandle,Perl_newSViv,Perl_sv_2mortal,LookupPrivilegeValueA,AdjustTokenPrivileges,Perl_croak_nocontext,Perl_sv_2pv_flags,IsValidSid,LookupAccountSidA,Perl_sv_2pv_flags,Perl_sv_setpv,Perl_sv_setpv,Perl_sv_setpv,Perl_sv_setiv,Perl_croak_nocontext,Perl_sv_2pv_flags,Perl_sv_2pv_flags,LookupAccountNameA,Perl_sv_setpv,Perl_sv_setpvn,Perl_sv_setiv,Perl_croak_nocontext,LoadLibraryA,GetProcAddress,Perl_stack_grow,Perl_newSViv,Perl_sv_2mortal,FreeLibrary,FreeLibrary,GetProcAddress,Perl_warn_nocontext,FreeLibrary,GetCurrentThread,GetCurrentProcess,Perl_safesysmalloc,Perl_safesysfree,CloseHandle,FreeLibrary,Perl_newSViv,Perl_sv_2mortal,Perl_warn_nocontext,Perl_warn_nocontext,Perl_safesysfree,CloseHandle,FreeLibrary,Perl_stack_grow,Perl_warn_nocontext,FreeLibrary,Perl_warn_nocontext,Perl_croak_nocontext, 15_2_70843DEC
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_708441EC InitiateSystemShutdownA,AdjustTokenPrivileges,CloseHandle,Perl_newSViv,Perl_sv_2mortal, 15_2_708441EC
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004565A8 GetModuleHandleA,GetProcAddress,GetDiskFreeSpaceExA,GetDiskFreeSpaceA, 1_2_004565A8
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00456DD4 CoCreateInstance,CoCreateInstance,SysFreeString,SysFreeString, 1_2_00456DD4
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_0040A0D4 FindResourceA,SizeofResource,LoadResource,LockResource, 0_2_0040A0D4
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Users\user\AppData\Local\Programs Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4052:120:WilError_03
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Mutant created: \Sessions\1\BaseNamedObjects\madExceptSettingsMtx$8fc
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Mutant created: NULL
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Mutant created: \Sessions\1\BaseNamedObjects\HookTThread$8fc
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5896:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2260:120:WilError_03
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Mutant created: \Sessions\1\BaseNamedObjects\GeoSetterStartOnlyOnce
Source: C:\Users\user\Desktop\geosetter_setup.exe File created: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp Jump to behavior
Source: Yara match File source: 7.0.GeoSetter.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp, type: MEMORY
Source: Yara match File source: C:\Program Files (x86)\GeoSetter\tools\is-V94I6.tmp, type: DROPPED
Source: Yara match File source: C:\Program Files (x86)\GeoSetter\is-07QKO.tmp, type: DROPPED
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File read: C:\Windows\win.ini Jump to behavior
Source: C:\Users\user\Desktop\geosetter_setup.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: geosetter_setup.exe String found in binary or memory: need to be updated. /RESTARTAPPLICATIONS Instructs Setup to restart applications. /NORESTARTAPPLICATIONS Prevents Setup from restarting applications. /LOADINF="filename" Instructs Setup to load the settings from the specified file after having checked t
Source: C:\Users\user\Desktop\geosetter_setup.exe File read: C:\Users\user\Desktop\geosetter_setup.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\geosetter_setup.exe "C:\Users\user\Desktop\geosetter_setup.exe"
Source: C:\Users\user\Desktop\geosetter_setup.exe Process created: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp "C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp" /SL5="$20442,24249229,57856,C:\Users\user\Desktop\geosetter_setup.exe"
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\GeoSetter\GeoSetterShellExt.dll"
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\GeoSetter\GeoSetterShellExt64.dll"
Source: C:\Windows\SysWOW64\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files (x86)\GeoSetter\GeoSetterShellExt64.dll"
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process created: C:\Program Files (x86)\GeoSetter\GeoSetter.exe "C:\Program Files (x86)\GeoSetter\GeoSetter.exe"
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe "C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe" -listx
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe -listx
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe "C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe" -lang
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe -lang
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe "C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe" -ver
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe -ver
Source: C:\Users\user\Desktop\geosetter_setup.exe Process created: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp "C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp" /SL5="$20442,24249229,57856,C:\Users\user\Desktop\geosetter_setup.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\GeoSetter\GeoSetterShellExt.dll" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\GeoSetter\GeoSetterShellExt64.dll" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process created: C:\Program Files (x86)\GeoSetter\GeoSetter.exe "C:\Program Files (x86)\GeoSetter\GeoSetter.exe" Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files (x86)\GeoSetter\GeoSetterShellExt64.dll" Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe "C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe" -listx Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe "C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe" -lang Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe "C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe" -ver Jump to behavior
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe -listx Jump to behavior
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe -lang
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe -ver
Source: C:\Users\user\Desktop\geosetter_setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\geosetter_setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: avifil32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: msvfw32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: msvfw32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: faultrep.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: shunimpl.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: olepro32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: mscms.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: coloradapterclient.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: security.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: idndl.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: c_is2022.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: c_g18030.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: c_gsm7.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: c_iscii.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: ieframe.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: riched32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: samlib.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: dcrawlib.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: msiso.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: mshtml.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: thumbcache.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: srpapi.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: mlang.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: jscript9.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: libeay32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: ssleay32.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: perl524.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: perl524.dll
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: perl524.dll
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32 Jump to behavior
Source: GeoSetter.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\GeoSetter\GeoSetter.exe
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File written: C:\Users\user\AppData\Roaming\GeoSetter\config.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Window found: window name: TSelectLanguageForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: OK
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Automated click: I accept the agreement
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Automated click: OK
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Windows\SysWOW64\RICHED32.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.DisclaimerThis software is provided "as-is". No warranty of any kind is expressed or implied. You use at your own risk. The author will not be liable for data loss damages loss of profits or any other kind of loss while using or misusing this software.FreewareThis program is freeware - that means you can download and copy it. You can even use it for commercial purposes however the sale of this software is prohibited.If you are an editor and wish to include GeoSetter on a magazine's CD or DVD please contact me.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.DisclaimerThis software is provided "as-is". No warranty of any kind is expressed or implied. You use at your own risk. The author will not be liable for data loss damages loss of profits or any other kind of loss while using or misusing this software.FreewareThis program is freeware - that means you can download and copy it. You can even use it for commercial purposes however the sale of this software is prohibited.If you are an editor and wish to include GeoSetter on a magazine's CD or DVD please contact me.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: geosetter_setup.exe Static file information: File size 24564453 > 1048576
Source: geosetter_setup.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00450994 GetVersion,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 1_2_00450994
Source: is-5LPT9.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0xbf086
Source: is-QSPTB.tmp.1.dr Static PE information: real checksum: 0x1f64a3 should be: 0x8013a0
Source: is-V94I6.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0x1dd75
Source: exiftool.exe.7.dr Static PE information: real checksum: 0x1f64a3 should be: 0x8013a0
Source: is-KONM9.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0x536fb
Source: geosetter_setup.tmp.0.dr Static PE information: real checksum: 0x0 should be: 0xb33d1
Source: is-LEN5V.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0x87192
Source: is-1BDNO.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0xbcd2a
Source: is-LEN5V.tmp.1.dr Static PE information: section name: .stab
Source: is-LEN5V.tmp.1.dr Static PE information: section name: .stabstr
Source: is-5LPT9.tmp.1.dr Static PE information: section name: /4
Source: is-5LPT9.tmp.1.dr Static PE information: section name: /16
Source: is-5LPT9.tmp.1.dr Static PE information: section name: /30
Source: is-5LPT9.tmp.1.dr Static PE information: section name: /42
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\GeoSetter\GeoSetterShellExt.dll"
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_00406A18 push 00406A55h; ret 0_2_00406A4D
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_004040B5 push eax; ret 0_2_004040F1
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_00404185 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_00404206 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_004042E8 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_00404283 push 00404391h; ret 0_2_00404389
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_004093B4 push 004093E7h; ret 0_2_004093DF
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_00408580 push ecx; mov dword ptr [esp], eax 0_2_00408585
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00409D9C push 00409DD9h; ret 1_2_00409DD1
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0041A078 push ecx; mov dword ptr [esp], ecx 1_2_0041A07D
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00452100 push ecx; mov dword ptr [esp], eax 1_2_00452105
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0040A273 push ds; ret 1_2_0040A29D
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004062C4 push ecx; mov dword ptr [esp], eax 1_2_004062C5
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0040A29F push ds; ret 1_2_0040A2A0
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00460518 push ecx; mov dword ptr [esp], ecx 1_2_0046051C
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00496594 push ecx; mov dword ptr [esp], ecx 1_2_00496599
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004587B4 push 004587ECh; ret 1_2_004587E4
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00410930 push ecx; mov dword ptr [esp], edx 1_2_00410935
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00486A94 push ecx; mov dword ptr [esp], ecx 1_2_00486A99
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00478D50 push ecx; mov dword ptr [esp], edx 1_2_00478D51
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00412D78 push 00412DDBh; ret 1_2_00412DD3
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0040D288 push ecx; mov dword ptr [esp], edx 1_2_0040D28A
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0040546D push eax; ret 1_2_004054A9
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0040553D push 00405749h; ret 1_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004055BE push 00405749h; ret 1_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0040563B push 00405749h; ret 1_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004056A0 push 00405749h; ret 1_2_00405741
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0040F7E8 push ecx; mov dword ptr [esp], edx 1_2_0040F7EA
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004438E0 push ecx; mov dword ptr [esp], ecx 1_2_004438E4
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00459ACC push 00459B10h; ret 1_2_00459B08
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0049BD44 pushad ; retf 1_2_0049BD53
Source: is-P21BL.tmp.1.dr Static PE information: section name: .text entropy: 6.807704201137633
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\is-KONM9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8b4e2b00.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bc3918b8.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\IO\IO.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Digest\MD5\MD5.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Digest\SHA\SHA.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\ielib32.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\is-07QKO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Time\Piece\Piece.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\mro\mro.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\is-HJO89.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\is-OMIVA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Socket\Socket.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Cwd\Cwd.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Compress\Raw\Bzip2\Bzip2.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e8ce9e63.dll Jump to dropped file
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\perl524.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\tools\is-V94I6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\DelZip190.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\0b174c5f.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9e2b3cdd.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e5acedbf.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\is-5LPT9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32\FindFile\FindFile.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\30e95417.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\GeoSetterShellExt.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Time\HiRes\HiRes.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\GeoSetterShellExt64.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32\API\API.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\54f7af00.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Math\BigInt\GMP\GMP.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a09139d7.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\tools\exiftool.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32\Win32.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\File\Glob\Glob.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\is-1BDNO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\tools\consoleStartHelper.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\is-B0F3I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6b9bcbc1.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\MIME\Base64\Base64.dll Jump to dropped file
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32\Console\Console.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\List\Util\Util.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\72279688.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\tools\is-QSPTB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32API\File\File.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\is-LEN5V.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Math\BigInt\FastCalc\FastCalc.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\dcrawlib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Fcntl\Fcntl.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\re\re.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\libeay32.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\GeoSetter.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\is-P21BL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Program Files (x86)\GeoSetter\ssleay32.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\7f720997.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\25bbf886.dll Jump to dropped file
Source: C:\Users\user\Desktop\geosetter_setup.exe File created: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Encode\Encode.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\POSIX\POSIX.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe File created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Compress\Raw\Zlib\Zlib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\Users\user\AppData\Local\Temp\is-BDALQ.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GeoSetter Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GeoSetter\GeoSetter.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0042405C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, 1_2_0042405C
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0042405C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, 1_2_0042405C
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00422CAC SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, 1_2_00422CAC
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0041811E IsIconic,SetWindowPos, 1_2_0041811E
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00418120 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, 1_2_00418120
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004245E4 IsIconic,SetActiveWindow, 1_2_004245E4
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0042462C IsIconic,SetActiveWindow,SetFocus, 1_2_0042462C
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004187D4 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, 1_2_004187D4
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00484D28 IsIconic,GetWindowLongA,ShowWindow,ShowWindow, 1_2_00484D28
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0042F71C IsIconic,GetWindowLongA,GetWindowLongA,GetActiveWindow,MessageBoxA,SetActiveWindow,GetActiveWindow,MessageBoxA,SetActiveWindow, 1_2_0042F71C
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004179E8 IsIconic,GetCapture, 1_2_004179E8
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0041F568 GetVersion,SetErrorMode,LoadLibraryA,SetErrorMode,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary, 1_2_0041F568
Source: C:\Users\user\Desktop\geosetter_setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: A5F0000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: A9A0000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: AB20000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: AB40000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: BC20000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: BCE0000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: BD80000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: BDE0000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: BE00000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: BE60000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: BE80000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: BEA0000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: BEC0000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Window / User API: threadDelayed 1920 Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Window / User API: threadDelayed 7634 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\is-KONM9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8b4e2b00.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bc3918b8.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\IO\IO.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Digest\MD5\MD5.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Digest\SHA\SHA.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\ielib32.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Time\Piece\Piece.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\mro\mro.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\is-HJO89.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\is-OMIVA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Socket\Socket.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Cwd\Cwd.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Compress\Raw\Bzip2\Bzip2.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e8ce9e63.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\DelZip190.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\tools\is-V94I6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\0b174c5f.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9e2b3cdd.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e5acedbf.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\is-5LPT9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\30e95417.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32\FindFile\FindFile.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\GeoSetterShellExt.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Time\HiRes\HiRes.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\GeoSetterShellExt64.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32\API\API.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\54f7af00.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Math\BigInt\GMP\GMP.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a09139d7.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32\Win32.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\File\Glob\Glob.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\is-1BDNO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\tools\consoleStartHelper.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\is-B0F3I.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6b9bcbc1.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\MIME\Base64\Base64.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32\Console\Console.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\List\Util\Util.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\72279688.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Win32API\File\File.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\is-LEN5V.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Math\BigInt\FastCalc\FastCalc.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Fcntl\Fcntl.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\re\re.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\GeoSetter\is-P21BL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\7f720997.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\25bbf886.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Encode\Encode.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\POSIX\POSIX.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\auto\Compress\Raw\Zlib\Zlib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-BDALQ.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\Desktop\geosetter_setup.exe Evasive API call chain: GetSystemTime,DecisionNodes
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe API coverage: 0.1 %
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe TID: 5144 Thread sleep time: -76340s >= -30000s Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Thread sleep count: Count: 1920 delay: -10 Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Thread sleep count: Count: 7634 delay: -10 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00476120 FindFirstFileA,FindNextFileA,FindClose, 1_2_00476120
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004531A4 FindFirstFileA,GetLastError, 1_2_004531A4
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_004648D0 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_004648D0
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00464D4C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode, 1_2_00464D4C
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00463344 FindFirstFileA,FindNextFileA,FindClose, 1_2_00463344
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0049998C FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose, 1_2_0049998C
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC0AEB0 win32_opendir,strlen,Perl_safesyscalloc,strcpy,MultiByteToWideChar,Perl_get_context,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,strlen,Perl_safesysmalloc,strcpy,GetLastError,_errno,WideCharToMultiByte,_errno,_errno,Perl_safesysfree,_errno,_errno, 15_2_6DC0AEB0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC0BB70 win32_longpath,strcpy,FindFirstFileA,strcpy,FindClose,_errno,FindClose,_errno, 15_2_6DC0BB70
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_70845F80 PL_charclass,wcscpy,FindFirstFileW,wcslen,wcscpy,FindClose,_errno,FindClose,_errno,toupper, 15_2_70845F80
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_70845BA0 PL_charclass,_mbscpy,FindFirstFileA,_mbscpy,FindClose,toupper,_errno,FindClose,_errno, 15_2_70845BA0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6560A76C Perl_get_context,Perl_get_context,Perl_get_context,GetLogicalDriveStringsA,Perl_get_context,Perl_get_context,Perl_get_context,Perl_get_context,Perl_get_context,Perl_sv_newmortal,Perl_get_context,Perl_sv_setuv,Perl_get_context,Perl_get_context,Perl_get_context,Perl_get_context,Perl_get_context, 15_2_6560A76C
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_0040A018 GetSystemInfo,VirtualQuery,VirtualProtect,VirtualProtect,VirtualQuery, 0_2_0040A018
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData\Local\Microsoft\Windows Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData\Local\Microsoft Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData\Local Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe File opened: C:\Users\user\AppData\Local\Microsoft\Windows\History\desktop.ini Jump to behavior
Source: geosetter_setup.tmp, 00000001.00000003.2458983625.000000000076D000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: geosetter_setup.tmp, 00000001.00000003.2458983625.000000000076D000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Process information queried: ProcessInformation Jump to behavior

Anti Debugging

barindex
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Debugger detection routine: QueryPerformanceCounter, DebugActiveProcess, DecisionNodes, ExitProcess or Sleep
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Debugger detection routine: QueryPerformanceCounter, DebugActiveProcess, DecisionNodes, ExitProcess or Sleep
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_62103C50 IsDebuggerPresent,Perl_croak_nocontext, 15_2_62103C50
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00450994 GetVersion,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 1_2_00450994
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Code function: 9_2_00401180 Sleep,Sleep,SetUnhandledExceptionFilter,GetProcAddress,_acmdln,malloc,strlen,malloc,memcpy,__initenv,_cexit,_amsg_exit,_initterm,GetStartupInfoA,_initterm,exit, 9_2_00401180
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Code function: 9_2_00404700 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 9_2_00404700
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_00401180 Sleep,Sleep,SetUnhandledExceptionFilter,GetProcAddress,_acmdln,malloc,strlen,malloc,memcpy,__initenv,_cexit,_amsg_exit,_initterm,GetStartupInfoA,_initterm,exit, 15_2_00401180
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_004064F0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_004064F0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_62104560 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_62104560
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_62583410 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_62583410
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_62AC27C0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_62AC27C0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_62D89200 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_62D89200
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_64FC2E30 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_64FC2E30
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6560FC30 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_6560FC30
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_66A140E0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_66A140E0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_66E02810 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_66E02810
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_674C3960 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_674C3960
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6A5466D0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_6A5466D0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC1BB70 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort,EnterCriticalSection,TlsGetValue,GetLastError,TlsGetValue,GetLastError,LeaveCriticalSection, 15_2_6DC1BB70
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_707C48D0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_707C48D0
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_70848340 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_70848340
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0047974C ShellExecuteEx,GetLastError,MsgWaitForMultipleObjects,GetExitCodeProcess,CloseHandle, 1_2_0047974C
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe "C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe" -listx Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe "C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe" -lang Jump to behavior
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Process created: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe "C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe" -ver Jump to behavior
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe -listx Jump to behavior
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe -lang
Source: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe Process created: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe -ver
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0042F254 InitializeSecurityDescriptor,SetSecurityDescriptorDacl,CreateMutexA, 1_2_0042F254
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_0042E4EC AllocateAndInitializeSid,GetVersion,GetModuleHandleA,GetProcAddress,CheckTokenMembership,GetCurrentThread,OpenThreadToken,GetLastError,GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetLastError,GetTokenInformation,EqualSid,CloseHandle,FreeSid, 1_2_0042E4EC
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp Binary or memory string: Shell_TrayWnd
Source: GeoSetter.exe, 00000007.00000000.2454380438.0000000000401000.00000020.00000001.01000000.0000000B.sdmp Binary or memory string: Shell_TrayWndS
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: GetLocaleInfoA, 0_2_0040565C
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: GetLocaleInfoA, 0_2_004056A8
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: GetLocaleInfoA, 1_2_004089B8
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: GetLocaleInfoA, 1_2_00408A04
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\0b174c5f.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\0b174c5f.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\54f7af00.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\54f7af00.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6b9bcbc1.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6b9bcbc1.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\72279688.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\72279688.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\7f720997.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\7f720997.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8b4e2b00.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9e2b3cdd.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a09139d7.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a09139d7.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bc3918b8.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bc3918b8.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e5acedbf.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e5acedbf.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e8ce9e63.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e8ce9e63.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4026afd7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4026afd7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4026afd7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b8008417.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b8008417.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b8008417.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b8008417.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\349957b9.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\349957b9.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\349957b9.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\349957b9.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6bc3ec17.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6bc3ec17.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6bc3ec17.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6bc3ec17.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3165f85e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3165f85e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3165f85e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3165f85e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\db3a8f47.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\db3a8f47.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\17d23068.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\17d23068.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\17d23068.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b9ab5c31.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b9ab5c31.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b9ab5c31.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\7988408f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\7988408f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\7988408f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a1570d38.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a1570d38.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a1570d38.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\045009c7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\045009c7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\045009c7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e65dd41e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e65dd41e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e65dd41e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\e65dd41e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3b9419e9.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3b9419e9.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3b9419e9.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\5af8b25a.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\5af8b25a.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\5af8b25a.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\f0d492b4.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\f0d492b4.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\f0d492b4.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\f0d492b4.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3adf7875.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3adf7875.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3adf7875.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c7a3bee2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c7a3bee2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b1f1d539.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b1f1d539.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b1f1d539.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b2f30932.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b2f30932.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b2f30932.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\0afcf8e6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\0afcf8e6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\0afcf8e6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\de029105.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\de029105.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\de029105.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\de029105.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\468d9f90.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\468d9f90.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\468d9f90.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\468d9f90.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\468fc7f6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\468fc7f6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\468fc7f6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3b049f92.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3b049f92.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3b049f92.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3b049f92.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bf6d9a1a.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bf6d9a1a.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\79c8e6ca.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\79c8e6ca.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\79c8e6ca.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\79c8e6ca.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\1178e293.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\1178e293.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\1178e293.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\21cbf464.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\21cbf464.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\21cbf464.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\21cbf464.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\43d13a5e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\43d13a5e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\43d13a5e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c6bedb53.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c6bedb53.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bb11a8f0.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bb11a8f0.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bb11a8f0.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4645d576.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4645d576.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4645d576.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\16e95c68.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\16e95c68.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\16e95c68.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\16e95c68.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4a13db57.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4a13db57.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4a13db57.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\377a5d44.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\377a5d44.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\52e5967c.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2559a606.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2559a606.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2559a606.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2559a606.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\5e4a9ee7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\5e4a9ee7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\5e4a9ee7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\49975809.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\49975809.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\49975809.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\49975809.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8787f619.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8787f619.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8787f619.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8787f619.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\29785c3a.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\29785c3a.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c085c1f8.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c085c1f8.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c085c1f8.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\ec189ba7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\ec189ba7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9a5ed9f6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9a5ed9f6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9a5ed9f6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9a5ed9f6.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d4702f47.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d4702f47.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d4702f47.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bbb12565.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bbb12565.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bbb12565.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\bbb12565.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2acf1aa3.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2acf1aa3.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\907352b2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\907352b2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\907352b2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\783170a4.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\783170a4.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\aff11a74.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\aff11a74.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\aff11a74.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\aff11a74.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9063d34b.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9063d34b.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9063d34b.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\79c927d5.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\79c927d5.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\79c927d5.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\79c927d5.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3f264ab3.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3f264ab3.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3f264ab3.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6b6f046e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4c9f24be.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4c9f24be.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\ff4fd2ad.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\ff4fd2ad.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d93ed23f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d93ed23f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d93ed23f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d93ed23f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\72e7eaee.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\72e7eaee.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\72e7eaee.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\249772ec.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\249772ec.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\249772ec.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\04d2846b.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\04d2846b.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\04d2846b.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c314314f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c314314f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c314314f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2d37d675.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2d37d675.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\ed3edee5.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\ed3edee5.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\ed3edee5.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8fb705b3.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8fb705b3.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\8fb705b3.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d24ed0ef.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d24ed0ef.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d24ed0ef.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\eb2860e2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\eb2860e2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\eb2860e2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\eb2860e2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3957efc2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\3957efc2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\ab8b3e5d.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\ab8b3e5d.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\754a1dd1.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\754a1dd1.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\754a1dd1.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\754a1dd1.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\45e7adef.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\45e7adef.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\45e7adef.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\45e7adef.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9086f052.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9086f052.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9086f052.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\9086f052.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b0050406.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b0050406.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\b0050406.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\1ad88610.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\1ad88610.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\1ad88610.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\1ad88610.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d41d2520.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d41d2520.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d41d2520.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\d41d2520.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2b62678e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2b62678e.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a2f5f87c.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a2f5f87c.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\a2f5f87c.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\74517a94.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\74517a94.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\11a6f85f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\11a6f85f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\11a6f85f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\11a6f85f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6dfbd852.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6dfbd852.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\6dfbd852.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2de0fc63.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2de0fc63.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\2de0fc63.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\f29f117f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\f29f117f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\f29f117f.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4c9ab222.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4c9ab222.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4c9ab222.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\4c9ab222.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\fea1f3e7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\fea1f3e7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\fea1f3e7.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c67b85ca.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\c67b85ca.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\MANIFEST VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\META.yml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\META.yml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\ActivePerl\Config.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Archive\Zip.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Archive\Zip\Archive.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Archive\Zip\DirectoryMember.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Archive\Zip\FileMember.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Archive\Zip\Member.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Archive\Zip\NewFileMember.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Archive\Zip\ZipFileMember.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Archive\Zip\ZipFileMember.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Carp.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Class\Struct.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Compress\Raw\Bzip2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Compress\Raw\Bzip2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Compress\Raw\Zlib.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Compress\Raw\Zlib.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Compress\Zlib.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Compress\Zlib.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Config.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Config_git.pl VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Config_heavy.pl VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Config_heavy.pl VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Cwd.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Digest\MD5.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Digest\base.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\DynaLoader.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\DynaLoader.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Encode\Alias.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Encode\Config.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Encode\Encoding.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Encode\MIME\Name.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Errno.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Exporter.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\Fcntl.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Basename.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Copy.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Find.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Glob.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Glob.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\GlobMapper.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\GlobMapper.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Path.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Path.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\RandomAccess.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Spec.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Spec.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Spec\Unix.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Spec\Win32.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Spec\Win32.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\Temp.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\File\stat.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\FileHandle.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Adapter\Bzip2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Adapter\Bzip2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Adapter\Deflate.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Base.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Base\Common.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Base\Common.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Bzip2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Bzip2.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Gzip.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Gzip.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\RawDeflate.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\RawDeflate.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Compress\Zlib\Extra.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Dir.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\File.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\File.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Handle.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Pipe.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Seekable.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Select.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Select.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Socket.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Socket\INET.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Socket\UNIX.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Uncompress\Adapter\Inflate.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Uncompress\Adapter\Inflate.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Uncompress\Base.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\inc\lib\IO\Uncompress\Base.pm VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Queries volume information: C:\Users\user\AppData\Roaming\GeoSetter\tools\exiftool.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00458DC4 GetTickCount,QueryPerformanceCounter,GetSystemTimeAsFileTime,GetCurrentProcessId,CreateNamedPipeA,GetLastError,CreateFileA,SetNamedPipeHandleState,CreateProcessA,CloseHandle,CloseHandle, 1_2_00458DC4
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_004026C4 GetSystemTime, 0_2_004026C4
Source: C:\Users\user\AppData\Local\Temp\is-OLKP3.tmp\geosetter_setup.tmp Code function: 1_2_00455D38 GetUserNameA, 1_2_00455D38
Source: C:\Users\user\Desktop\geosetter_setup.exe Code function: 0_2_00404654 GetModuleHandleA,GetVersion,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,SetProcessDEPPolicy, 0_2_00404654
Source: C:\Program Files (x86)\GeoSetter\GeoSetter.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC12260 win32_listen,_get_osfhandle,listen,WSAGetLastError,_errno,SetLastError, 15_2_6DC12260
Source: C:\Users\user\AppData\Local\Temp\par-616c666f6e73\cache-exiftool-10.96\exiftool.exe Code function: 15_2_6DC11EF0 win32_bind,_get_osfhandle,bind,WSAGetLastError,_errno,SetLastError, 15_2_6DC11EF0
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs