Windows Analysis Report
h32trial.exe

Overview

General Information

Sample name: h32trial.exe
Analysis ID: 1416969
MD5: eb2bf9d3d51f4f4c866933a0a7938be4
SHA1: faf78b4e641a8d583d565556ac189cf7af2f796d
SHA256: 5bf7ae786d283912cb409fc5c580e1db95ab067eb0ccfbc1aee4ae4cfe6ef866
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for dropped file
Sigma detected: Potential Persistence Via App Paths Default Property
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Queries the volume information (name, serial number etc) of a device
Registers a DLL
Sigma detected: Use Short Name Path in Command Line
Stores files to the Windows start menu directory
Stores large binary data to the registry
Tries to load missing DLLs
Uses 32bit PE files

Classification

AV Detection

barindex
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE (copy) Virustotal: Detection: 11% Perma Link
Source: C:\Program Files (x86)\HAWin32\~GLH001b.TMP Virustotal: Detection: 10% Perma Link
Source: h32trial.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\My Files\INSTALL.LOG
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\Local\Temp\GLF9373.tmp
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\Local\Temp\~GLH0000.TMP
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\Local\Temp\
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\Fonts\GLBSINST.%$D
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\Fonts\~GLH0011.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\Fonts\~GLH0012.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\Fonts\~GLH0013.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH005f.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0060.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0061.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0069.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH006a.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH006c.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH006e.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0070.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0071.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0072.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0074.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0075.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0079.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007b.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007c.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007d.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007e.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007f.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0080.TMP
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\PreviewSoft
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\PreviewSoft\HyperACCESS_8.4_6C2D.lic
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\PreviewSoft\HyperACCESS_8.4_6C2D.prf
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\SysWOW64\vboxb410.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\SysWOW64\vboxt410.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\SysWOW64\vboxp410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE File created: C:\Windows\SysWOW64\ws811164.ocx
Source: C:\Users\user\Desktop\h32trial.exe File deleted: C:\Windows\Fonts\GLBSINST.%$D
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: acgenral.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: winmm.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: samcli.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: msacm32.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: urlmon.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: mpr.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: sspicli.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: iertutil.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: srvcli.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: netutils.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: aclayers.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: sfc.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: sfc_os.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: riched32.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: riched20.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: usp10.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: msls31.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: propsys.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: profapi.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: edputil.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: appresolver.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: bcp47langs.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: slc.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: sppc.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: pcacli.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: cabinet.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: linkinfo.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: ntshrui.dll
Source: C:\Users\user\Desktop\h32trial.exe Section loaded: cscapi.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Section loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: rtvideo.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: olepro32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: rtvideo.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: rtvideo.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: vspell32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: mfcans32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: oc30.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: msvcrt20.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: msvcrt20.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: oc30loc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: oc30zzz.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: oc30zz.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: rtvideo.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Section loaded: mfc42.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: vbscript.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: jscript.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: iertutil.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: vspell32.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: mfcans32.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: oc30.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: msvcrt20.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: mfcans32.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: msvcrt20.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: oc30loc.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: oc30zzz.dll
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: oc30zz.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: apphelp.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: acgenral.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: winmm.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: samcli.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: msacm32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: version.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: userenv.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: urlmon.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: mpr.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: sspicli.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: iertutil.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: srvcli.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: netutils.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: aclayers.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: sfc.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: sfc_os.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: vboxp410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: vboxb410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: hadll32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: msvcp60.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: mfc42.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: msvcp60.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: mfc42.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: vboxt410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: wsock32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: mmdevapi.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: devobj.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: ksuser.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: avrt.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: audioses.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: powrprof.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: umpdc.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: midimap.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: resourcepolicyclient.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: textshaping.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: tapi32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: rtutils.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: hanxdrct.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: hanxsock.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: hanxssh.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: hanxtapi.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: wldp.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: propsys.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: policymanager.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Section loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: acgenral.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: samcli.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: msacm32.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: version.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: aclayers.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: sfc.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: sfc_os.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: riched32.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: riched20.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: usp10.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: msls31.dll
Source: C:\Program Files (x86)\HAWin32\register.exe Section loaded: textshaping.dll
Source: h32trial.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP
Source: classification engine Classification label: mal52.winEXE@21/130@0/0
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Mutant created: \Sessions\1\BaseNamedObjects\c:/windows/previewsoft/hyperaccess_8.4_6c2d.prf
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Mutant created: \Sessions\1\BaseNamedObjects\c:/windows/previewsoft/hyperaccess_8.4_6c2d.lic
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Mutant created: NULL
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Mutant created: \Sessions\1\BaseNamedObjects\software/classes/.drv/{d9e97102-346b-f906-a026-d15fd6b0f870}
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Mutant created: \Sessions\1\BaseNamedObjects\c:/windows/system32/ws811164.ocx
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Mutant created: \Sessions\1\BaseNamedObjects\c:/os985612.bin
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Mutant created: \Sessions\1\BaseNamedObjects\23fU4oq5ctI507Wg
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Mutant created: \Sessions\1\BaseNamedObjects\clsid/{181c4948-d1f3-d43f-d06a-c59969205125}
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Mutant created: \Sessions\1\BaseNamedObjects\mHWDTtNqqVWdr-Dv
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Local\Temp\GLC8787.tmp
Source: h32trial.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\h32trial.exe File read: C:\Users\user\Desktop\desktop.ini
Source: C:\Users\user\Desktop\h32trial.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\h32trial.exe File read: C:\Users\user\Desktop\h32trial.exe
Source: unknown Process created: C:\Users\user\Desktop\h32trial.exe "C:\Users\user\Desktop\h32trial.exe"
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\vsetupt.exe "C:\Users\user\AppData\Local\Temp\vsetupt.exe"
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp "C:\Users\user\AppData\Local\Temp\GLJ8798.tmp" C:\Windows\System32\olepro32.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp "C:\Users\user\AppData\Local\Temp\GLJ8798.tmp" C:\Windows\System32\oleaut32.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp "C:\Users\user\AppData\Local\Temp\GLJ8798.tmp" C:\Windows\System32\VSPELL32.OCX
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp "C:\Users\user\AppData\Local\Temp\GLJ8798.tmp" C:\Windows\System32\mfc42.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vbscript.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s jscript.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vspell32.ocx
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Program Files (x86)\HAWin32\HAWIN32.EXE "C:\PROGRA~2\HAWin32\HAWIN32.EXE"
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\vsetupt.exe "C:\Users\user\AppData\Local\Temp\vsetupt.exe"
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp "C:\Users\user\AppData\Local\Temp\GLJ8798.tmp" C:\Windows\System32\olepro32.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp "C:\Users\user\AppData\Local\Temp\GLJ8798.tmp" C:\Windows\System32\oleaut32.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp "C:\Users\user\AppData\Local\Temp\GLJ8798.tmp" C:\Windows\System32\VSPELL32.OCX
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp "C:\Users\user\AppData\Local\Temp\GLJ8798.tmp" C:\Windows\System32\mfc42.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vbscript.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s jscript.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vspell32.ocx
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Program Files (x86)\HAWin32\HAWIN32.EXE "C:\PROGRA~2\HAWin32\HAWIN32.EXE"
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process created: C:\Program Files (x86)\HAWin32\register.exe C:\PROGRA~2\HAWin32\register.exe /Product="HyperACCESS" /Version="9.11" /Serial="NAT6274A625"
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process created: C:\Program Files (x86)\HAWin32\register.exe C:\PROGRA~2\HAWin32\register.exe /Product="HyperACCESS" /Version="9.11" /Serial="NAT6274A625"
Source: C:\Users\user\Desktop\h32trial.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Window found: window name: SysTabControl32
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Windows\SysWOW64\RICHED32.DLL
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Window detected: Number of UI elements: 15
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Window detected: Number of UI elements: 15
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Window detected: Number of UI elements: 20
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Window detected: Number of UI elements: 21
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Window detected: Number of UI elements: 21
Source: C:\Program Files (x86)\HAWin32\register.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\8.0\Outlook\OMI Account Manager
Source: h32trial.exe Static file information: File size 8039501 > 1048576
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vbscript.dll
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0071.TMP Jump to dropped file
Source: C:\Program Files (x86)\HAWin32\register.exe File created: C:\Users\user\AppData\Local\Temp\GLMC3F0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0055.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH000e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0038.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH006c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0080.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Local\Temp\GLC8787.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0004.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007b.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Local\Temp\~GLH0005.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\My Files\~GLH0001.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0054.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH001d.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH003a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH006e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\Fonts\~GLH0011.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH005f.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0061.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\Fonts\~GLH0012.TMP Jump to dropped file
Source: C:\Program Files (x86)\HAWin32\register.exe File created: C:\Users\user\AppData\Local\Temp\GLCC3EF.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0020.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH002c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0046.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH006a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0060.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0036.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0082.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH004a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0069.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0006.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007d.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH002e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0048.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0072.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0052.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0040.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0022.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH001b.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0042.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0050.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH004c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0008.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH003e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007f.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0034.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH000a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0024.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0075.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0074.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0059.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0007.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Local\Temp\GLM899C.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0028.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH004e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\My Files\~GLH0002.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH000b.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH003c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0032.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0030.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Local\Temp\~GLH0000.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH000c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0026.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH000d.TMP Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\SysWOW64\vboxb410.dll Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH002a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0009.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\~GLH0044.TMP Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\SysWOW64\vboxp410.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\SysWOW64\vboxt410.dll Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH006a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0071.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0060.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007f.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH006c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0080.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0069.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007b.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007d.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0072.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH006e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\Fonts\~GLH0011.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0075.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH005f.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0061.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH0074.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\Fonts\~GLH0012.TMP Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\SysWOW64\vboxb410.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\SysWOW64\vboxp410.dll Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Windows\SysWOW64\~GLH007e.TMP Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe File created: C:\Windows\SysWOW64\vboxt410.dll Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Program Files (x86)\HAWin32\My Files\INSTALL.LOG
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS\Uninstall.lnk
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS Folder.lnk
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS.lnk
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS Host.lnk
Source: C:\Users\user\Desktop\h32trial.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS Graphics Viewer.lnk
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Hilgraeve\HAWin32\8.0 ConnectionKeys2
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\regsvr32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\register.exe Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0071.TMP Jump to dropped file
Source: C:\Program Files (x86)\HAWin32\register.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\GLMC3F0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0055.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\GLJ8798.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0038.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0080.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH006c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\GLC8787.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007b.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\My Files\~GLH0001.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0054.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH001d.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH003a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH006e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\Fonts\~GLH0011.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH005f.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0061.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\Fonts\~GLH0012.TMP Jump to dropped file
Source: C:\Program Files (x86)\HAWin32\register.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\GLCC3EF.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0020.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0046.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH002c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH006a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0060.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0036.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0082.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH004a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0069.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0006.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007d.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0048.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH002e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0072.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0052.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0040.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0022.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH001b.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0042.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0050.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH004c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0008.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007f.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH003e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0034.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0024.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0075.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0074.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0059.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\GLM899C.tmp Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0007.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0028.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH004e.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\My Files\~GLH0002.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000b.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH003c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0032.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0030.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\~GLH0000.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0026.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000c.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000d.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH002a.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0044.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe Dropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0009.TMP Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\Local\Temp\GLF9373.tmp
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\Local\Temp\~GLH0000.TMP
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\
Source: C:\Users\user\Desktop\h32trial.exe File opened: C:\Users\user\AppData\Local\Temp\
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Users\user\AppData\Local\Temp\vsetupt.exe "C:\Users\user\AppData\Local\Temp\vsetupt.exe"
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vbscript.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s jscript.dll
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vspell32.ocx
Source: C:\Users\user\Desktop\h32trial.exe Process created: C:\Program Files (x86)\HAWin32\HAWIN32.EXE "C:\PROGRA~2\HAWin32\HAWIN32.EXE"
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE Queries volume information: C:\ VolumeInformation
⊘No contacted IP infos