Windows Analysis Report
Predios.exe

Overview

General Information

Sample name: Predios.exe
Analysis ID: 1427676
MD5: b3f39d9d07c9ab215c5e204e7d1d46e8
SHA1: 9a3122ff03254992c5a0b3d34ac181316a217268
SHA256: 5e868e8eb5b82146457dc9381d68fb603e267c1ade4ba4ee5517be6afc70e33d
Infos:

Detection

Score: 3
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
Sigma detected: COM Hijacking via TreatAs
Sigma detected: Use Short Name Path in Command Line
Uses 32bit PE files

Classification

Source: Predios.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\data1.cab
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\
Source: Predios.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: clean3.winEXE@10/23@0/0
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\
Source: C:\Users\user\Desktop\Predios.exe File created: C:\Users\user\AppData\Local\Temp\plfDD4A.tmp
Source: Predios.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe File read: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.ini
Source: C:\Users\user\Desktop\Predios.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\Predios.exe File read: C:\Users\user\Desktop\Predios.exe
Source: unknown Process created: C:\Users\user\Desktop\Predios.exe "C:\Users\user\Desktop\Predios.exe"
Source: C:\Users\user\Desktop\Predios.exe Process created: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe "C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe"
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe" -RegServer
Source: unknown Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe C:\PROGRA~2\COMMON~1\INSTAL~1\Engine\6\INTEL3~1\IKernel.exe -Embedding
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe" /REGSERVER
Source: C:\Users\user\Desktop\Predios.exe Process created: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe "C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe"
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe" -RegServer
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe" /REGSERVER
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe" /UNREGSERVER
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe" /UNREGSERVER
Source: C:\Users\user\Desktop\Predios.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: acgenral.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: winmm.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: samcli.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: msacm32.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: urlmon.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: mpr.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: sspicli.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: iertutil.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: srvcli.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: netutils.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: aclayers.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: sfc.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: sfc_os.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: lz32.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: riched32.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: riched20.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: usp10.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: msls31.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\Predios.exe Section loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: acspecfc.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: mscms.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: ddraw.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: msi.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: coloradapterclient.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: dxgi.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: dciman32.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: cabinet.dll
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Section loaded: sxs.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acspecfc.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mscms.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ddraw.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coloradapterclient.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dciman32.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acgenral.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: samcli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msacm32.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: version.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: aclayers.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc_os.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wininet.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sxs.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acspecfc.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mscms.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ddraw.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coloradapterclient.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dciman32.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acgenral.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: samcli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msacm32.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: version.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: aclayers.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc_os.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wininet.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sxs.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: propsys.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: textshaping.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acspecfc.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mscms.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ddraw.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coloradapterclient.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dciman32.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acgenral.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: samcli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msacm32.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: version.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: aclayers.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc_os.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wininet.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sxs.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acspecfc.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mscms.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ddraw.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coloradapterclient.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dciman32.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acgenral.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: samcli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msacm32.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: version.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: aclayers.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc_os.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wininet.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sxs.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32
Source: C:\Users\user\Desktop\Predios.exe File written: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.ini
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Windows\SysWOW64\RICHED32.DLL
Source: Predios.exe Static file information: File size 2150764 > 1048576
Source: C:\Users\user\Desktop\Predios.exe File created: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{F4D57F79-B12B-4748-8D22-FEB5B3CF9A9D}\isrte383.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objee180.rra Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\temp.000 Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscre1be.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{F4D57F79-B12B-4748-8D22-FEB5B3CF9A9D}\_IsRe3a3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctore132.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iusee18f.rra Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\temp.000 Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{F4D57F79-B12B-4748-8D22-FEB5B3CF9A9D}\isrte383.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{F4D57F79-B12B-4748-8D22-FEB5B3CF9A9D}\_IsRe3a3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctore132.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objee180.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iusee18f.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscre1be.rra Jump to dropped file
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Predios.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objee180.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{F4D57F79-B12B-4748-8D22-FEB5B3CF9A9D}\isrte383.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscre1be.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{F4D57F79-B12B-4748-8D22-FEB5B3CF9A9D}\_IsRe3a3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctore132.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iusee18f.rra Jump to dropped file
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\AppData\Local\Temp\pftDD9A~tmp\Disk1\data1.cab
Source: C:\Users\user\Desktop\Predios.exe File opened: C:\Users\user\
⊘No contacted IP infos