Windows Analysis Report
SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe

Overview

General Information

Sample name: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe
Analysis ID: 1427767
MD5: 8745c960022bcefff65c91a47374a169
SHA1: e503dd1b85b17ba61e468890d11f3259e9437b72
SHA256: 8fd4a4dcbe8b649c8c8cec213352c6da213caaefffc76450efee498e51f63cda
Tags: exe
Infos:

Detection

Score: 32
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Compliance

Score: 35
Range: 0 - 100

Signatures

Multi AV Scanner detection for submitted file
Deletes itself after installation
Enables network access during safeboot for specific services
Found string related to ransomware
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Abnormal high CPU Usage
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to create guard pages, often used to hinder reverse engineering and debugging
Contains functionality to delete services
Contains functionality to launch a program with higher privileges
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Drops PE files
EXE planting / hijacking vulnerabilities found
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
JA3 SSL client fingerprint seen in connection with other malware
PE file contains an invalid checksum
PE file contains sections with non-standard names
Potential key logger detected (key state polling based)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Virustotal: Detection: 8% Perma Link
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMDownloader.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMInstaller.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Sss.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\PCStarter.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TMInstaller.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMService.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMLauncher.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\PCStarterXP.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TMRemover.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\InstallService.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\PCStarter.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMRemover.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TMLauncher.exe Jump to behavior

Compliance

barindex
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMDownloader.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMInstaller.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Sss.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\PCStarter.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TMInstaller.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMService.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMLauncher.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\PCStarterXP.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TMRemover.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\InstallService.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\PCStarter.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMRemover.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe EXE: C:\Users\user\AppData\Roaming\TurboMeeting\TMLauncher.exe Jump to behavior
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TurboMeeting Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user~1\AppData\Local\Temp\TMSetup.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user~1\AppData\Local\Temp\TMInstaller.txt Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\setup_status.txt Jump to behavior
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: certificate valid
Source: unknown HTTPS traffic detected: 8.18.62.6:443 -> 192.168.2.7:49706 version: TLS 1.2
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\RHUB2\PCSetup\Release.V2017\PCSetup.pdb source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000000.1308753930.0000000000E79000.00000002.00000001.01000000.00000003.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000002.1476961743.0000000000E79000.00000002.00000001.01000000.00000003.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\TMResource\Release.V2017\TMResource.pdb source: TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\PCInstaller\Release.V2017\PCInstaller.pdb source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500668690.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000000.1422829262.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\PCUninstaller\Release.V2017\PCUninstaller.pdb@ source: TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\MyHookDll\Release.V2017\MyHookDll.pdb source: TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: c:\dev\work\rhub\Code\SendSAS\release\SendSAS.pdb source: TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\vistafunc\Release.V2017\vistafunc.pdb source: TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000002.3778188999.000000006EC3D000.00000002.00000001.01000000.0000000A.sdmp, TurboMeeting.exe, 00000008.00000002.1527616968.000000006EC3D000.00000002.00000001.01000000.0000000A.sdmp, TurboMeeting.exe, 0000000B.00000002.1574382545.000000006EC3D000.00000002.00000001.01000000.0000000A.sdmp
Source: Binary string: C:\RHUB2\Code\PCUninstaller\Release.V2017\PCUninstaller.pdb source: TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\TMService\Release.V2017\TMService.pdb source: TMLauncher.exe, 00000004.00000003.1471373053.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\TMService\Release.V2017\TMService.pdbM source: TMLauncher.exe, 00000004.00000003.1471373053.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\PCGUI5\Release.V2017\TurboMeeting.pdb source: TurboMeeting.exe, 00000006.00000002.3776134929.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001889000.00000002.00000001.01000000.00000009.sdmp
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E14130 FindFirstFileW,RemoveDirectoryW,SetFileAttributesW,_strstr,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,GetLastError,FormatMessageW,WSAGetLastError, 0_2_00E14130
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E63648 FindFirstFileExW, 0_2_00E63648
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E338A9 __EH_prolog3_GS,GetFullPathNameW,PathIsUNCW,GetVolumeInformationW,CharUpperW,FindFirstFileW,FindClose, 0_2_00E338A9
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB4100 FindFirstFileW,RemoveDirectoryW,SetFileAttributesW,_strstr,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,GetLastError,FormatMessageW,WSAGetLastError, 4_2_00CB4100
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB1F00 GetFileAttributesW,CreateDirectoryW,WSAGetLastError,FindFirstFileW,GetLastError,FormatMessageW,FindNextFileW,SetFileAttributesW,CopyFileW,GetLastError,FormatMessageW,FindNextFileW,FindClose, 4_2_00CB1F00
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CC9155 SetLastError,FindFirstFileW,GetLastError, 4_2_00CC9155
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CC929D GetModuleHandleW,GetProcAddress,FindFirstFileW, 4_2_00CC929D
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CD9D08 __EH_prolog3_GS,GetFullPathNameW,PathIsUNCW,GetVolumeInformationW,CharUpperW,FindFirstFileW,FindClose, 4_2_00CD9D08
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CFDEE5 FindFirstFileExW, 4_2_00CFDEE5
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Code function: 6_2_6EC354E6 FindFirstFileExW, 6_2_6EC354E6
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData\Roaming\TurboMeeting Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml Jump to behavior

Networking

barindex
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Registry value created: NULL Service Jump to behavior
Source: Joe Sandbox View JA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E72440 InternetSetOptionA,InternetSetOptionA,InternetOpenA,InternetSetOptionA,WSAGetLastError,InternetSetOptionA,WSAGetLastError,InternetSetOptionA,WSAGetLastError,InternetConnectA,WSAGetLastError,HttpOpenRequestA,WSAGetLastError,InternetReadFile,InternetQueryOptionA,InternetSetOptionA,HttpSendRequestA,InternetReadFile,HttpSendRequestA,WSAGetLastError,HttpQueryInfoA,WSAGetLastError,InternetReadFile,GetDesktopWindow,InternetErrorDlg,WSAGetLastError,InternetReadFile,WSAGetLastError,InternetReadFileExA,WSAGetLastError,_strstr,WSAGetLastError, 0_2_00E72440
Source: global traffic HTTP traffic detected: GET /as/wapi/get_client_size?client_type=0&xml_format=Y&client=pc&myrand11262017=fsOpyNl7RRDmyVQ8cYMYTocPl4347283&rdm=1713420883 HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: support.lockwoodbroadcast.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /as/wapi/get_client?client_type=0&client=pc&myrand11262017=1s4z4AVItfvg3fyyYjjDdD6L2c347284&rdm=1713420884 HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: support.lockwoodbroadcast.comConnection: Keep-Alive
Source: unknown DNS traffic detected: queries for: support.lockwoodbroadcast.com
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000000.1308753930.0000000000E79000.00000002.00000001.01000000.00000003.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000002.1476961743.0000000000E79000.00000002.00000001.01000000.00000003.sdmp, TMLauncher.exe, 00000004.00000002.1500668690.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000000.1422829262.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://%s%shttp://%shttps://%s%shttps://%shttp://%s:%d%shttp://%s:%drhubcom.comgomeetnow.com.turbome
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://%s%shttps://%s%shttp://%s:%d%shttp://%s:%drhubcom.comgomeetnow.com.turbomeet.comgosupportnow.
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://%s/forumpost.php?euid=%s&cuid=%s&first_name=%s&last_name=%s&from_server_ip=%s&timer_id=%s
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://%s/forumpost.php?euid=%s&cuid=%s&first_name=%s&last_name=%s&from_server_ip=%s&timer_id=%sPMai
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://%s:%d/MeetingRegistration/user/update-meeting-info.php?sp=%s
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://%s:%d/MeetingRegistration/user/update-meeting-info.php?sp=%ssURL
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
Source: TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.thawte.com/ThawtePCA.crl0
Source: TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://https://https://%shttp://%sPCGUI.CInviteAttendee_::OnInitDialog.JoinMessage2PCGUI.CInviteAtte
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0C
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0H
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0I
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0O
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.sectigo.com0
Source: TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.thawte.com0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://s.symcb.com/universal-root.crl0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://s.symcd.com06
Source: TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://th.symcb.com/th.crl0
Source: TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://th.symcb.com/th.crt0
Source: TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://th.symcd.com0&
Source: TurboMeeting.exe, 00000006.00000000.1494408085.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001802000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://tools.ietf.org/html/draft-ietf-avtext-framemarking-07
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
Source: TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
Source: TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ts-ocsp.ws.symantec.com0;
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com/CPS0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0
Source: TurboMeeting.exe, 00000006.00000000.1494408085.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001802000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01
Source: TurboMeeting.exe, 0000000B.00000002.1573799950.000000001089C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.rhubcom.
Source: TurboMeeting.exe, 0000000B.00000002.1573799950.0000000010859000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.rhubcom.com
Source: TurboMeeting.exe, 00000006.00000000.1496181175.0000000001A8A000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1525335027.0000000001A8A000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1555133297.0000000001A8A000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.rhubcom.com.T
Source: TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.rhubcom.com0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500668690.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000000.1422829262.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.rhubcom.comRHUB
Source: TurboMeeting.exe, 00000006.00000000.1494408085.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001802000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-send-time
Source: TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001802000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/color-space
Source: TurboMeeting.exe, 00000006.00000000.1494408085.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001802000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor-00
Source: TurboMeeting.exe, 00000006.00000000.1494408085.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001802000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor-00http://www.webrtc.org/experi
Source: TurboMeeting.exe, 00000006.00000000.1494408085.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001802000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/playout-delay
Source: TurboMeeting.exe, 00000006.00000000.1494408085.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001802000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-content-type
Source: TurboMeeting.exe, 00000006.00000000.1494408085.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.0000000001802000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001802000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-timing
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: https://compose.mail.yahoo.com/?To=&Subj=
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://d.symcb.com/cps0%
Source: TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://d.symcb.com/rpa0
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://d.symcb.com/rpa0.
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: https://mail.google.com/mail/u/0/?view=cm&fs=1&tf=1&to&su=
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: https://mail.google.com/mail/u/0/?view=cm&fs=1&tf=1&to&su=https://compose.mail.yahoo.com/?To=&Subj=(
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1456768403.0000000000F99000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://sectigo.com/CPS0C
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: https://streams.videolan.org/upload/
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000002.1476645003.00000000004E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://support.lockwoodbroadcast.com/
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000002.1477353524.00000000044D0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476116809.0000000000522000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476116809.000000000052B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000002.1476684834.0000000000522000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://support.lockwoodbroadcast.com/as/wapi/get_client?client_type=0&client=pc&myrand11262017=1s4z
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000002.1476645003.0000000000513000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://support.lockwoodbroadcast.com/as/wapi/get_client_size?client_type=0&xml_format=Y&client=pc&m
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471373053.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471840687.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.digicert.com/CPS0
Source: TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp String found in binary or memory: https://www.google.com/calendar/render?action=TEMPLATE&text=
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown HTTPS traffic detected: 8.18.62.6:443 -> 192.168.2.7:49706 version: TLS 1.2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E218C5 GetKeyState,GetKeyState,GetKeyState,SendMessageW, 0_2_00E218C5
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CD03AF GetKeyState,GetKeyState,GetKeyState,SendMessageW, 4_2_00CD03AF

Spam, unwanted Advertisements and Ransom Demands

barindex
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: /as/wapi/login?XMLHTTPRequest=Y&Email=%s&Password=%s&RememberMe=%s&Version=%s&pass_through=%s&employee_uid=%s&run_service=%s&os_version=%d&os_description=%s&encrypted=Y
Source: TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: /as/wapi/login?XMLHTTPRequest=Y&Email=%s&Password=%s&RememberMe=%s&Version=%s&pass_through=%s&employee_uid=%s&run_service=%s&os_version=%d&os_description=%s&encrypted=Y
Source: TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: /as/wapi/login?XMLHTTPRequest=Y&Email=%s&Password=%s&RememberMe=%s&Version=%s&pass_through=%s&employee_uid=%s&run_service=%s&os_version=%d&os_description=%s&encrypted=Y
Source: TurboMeeting.exe, 00000008.00000000.1504992526.00000000016C2000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: /as/wapi/login?XMLHTTPRequest=Y&Email=%s&Password=%s&RememberMe=%s&Version=%s&pass_through=%s&employee_uid=%s&run_service=%s&os_version=%d&os_description=%s&encrypted=Y
Source: TurboMeeting.exe, 0000000B.00000000.1530054819.00000000016C2000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: /as/wapi/login?XMLHTTPRequest=Y&Email=%s&Password=%s&RememberMe=%s&Version=%s&pass_through=%s&employee_uid=%s&run_service=%s&os_version=%d&os_description=%s&encrypted=Y
Source: TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: /as/wapi/login?XMLHTTPRequest=Y&Email=%s&Password=%s&RememberMe=%s&Version=%s&pass_through=%s&employee_uid=%s&run_service=%s&os_version=%d&os_description=%s&encrypted=Y
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process Stats: CPU usage > 49%
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CA5C10 GetActiveWindow,MessageBoxW,Sleep,OpenSCManagerW,OpenServiceW,ControlService,Sleep,DeleteService,Sleep,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,WSAGetLastError,CloseServiceHandle,CloseServiceHandle,WSAGetLastError, 4_2_00CA5C10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E4CDF6 0_2_00E4CDF6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E70F20 0_2_00E70F20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E48099 0_2_00E48099
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E48343 0_2_00E48343
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E70330 0_2_00E70330
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E105F0 0_2_00E105F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E70620 0_2_00E70620
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E4860A 0_2_00E4860A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E488C5 0_2_00E488C5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E3C8D5 0_2_00E3C8D5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E6A8B6 0_2_00E6A8B6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E6A9DF 0_2_00E6A9DF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E70AE0 0_2_00E70AE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E06C90 0_2_00E06C90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E68E8F 0_2_00E68E8F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E10FD0 0_2_00E10FD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E4D026 0_2_00E4D026
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E6D010 0_2_00E6D010
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E4D256 0_2_00E4D256
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E4D4C0 0_2_00E4D4C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E37463 0_2_00E37463
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E71660 0_2_00E71660
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E6D7B0 0_2_00E6D7B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E478D0 0_2_00E478D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E5182F 0_2_00E5182F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E679B9 0_2_00E679B9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E5BA03 0_2_00E5BA03
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E51B86 0_2_00E51B86
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E53B80 0_2_00E53B80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E6FC10 0_2_00E6FC10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E47D27 0_2_00E47D27
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E1BF40 0_2_00E1BF40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E45F4A 0_2_00E45F4A
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE71E4 4_2_00CE71E4
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CF60D8 4_2_00CF60D8
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE2130 4_2_00CE2130
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D02269 4_2_00D02269
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CA8350 4_2_00CA8350
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE2377 4_2_00CE2377
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE0330 4_2_00CE0330
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CC6440 4_2_00CC6440
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D08580 4_2_00D08580
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE26E9 4_2_00CE26E9
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CA6660 4_2_00CA6660
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB08E5 4_2_00CB08E5
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D0A9E0 4_2_00D0A9E0
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE2993 4_2_00CE2993
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB2CC0 4_2_00CB2CC0
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE2C5A 4_2_00CE2C5A
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE2F15 4_2_00CE2F15
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CAD070 4_2_00CAD070
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D0B100 4_2_00D0B100
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB1257 4_2_00CB1257
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB122C 4_2_00CB122C
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CED3C0 4_2_00CED3C0
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D0B3F0 4_2_00D0B3F0
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB14D0 4_2_00CB14D0
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D054F4 4_2_00D054F4
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CEB45F 4_2_00CEB45F
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE7416 4_2_00CE7416
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE7648 4_2_00CE7648
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D05614 4_2_00D05614
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D0B8B0 4_2_00D0B8B0
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE78A5 4_2_00CE78A5
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D03BBF 4_2_00D03BBF
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00D07DE0 4_2_00D07DE0
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CFFFCC 4_2_00CFFFCC
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Code function: 6_2_6EC3B4B1 6_2_6EC3B4B1
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: String function: 00CDEBDC appears 84 times
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: String function: 00CA6620 appears 74 times
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: String function: 00CA6260 appears 34 times
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: String function: 00CAF930 appears 325 times
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: String function: 00CDECC0 appears 68 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: String function: 00E07CD0 appears 68 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: String function: 00E01D51 appears 33 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: String function: 00E441EB appears 34 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: String function: 00E44180 appears 115 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: String function: 00E44880 appears 67 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: String function: 00E0EEE0 appears 246 times
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Binary or memory string: OriginalFilename vs SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000000.1308827291.0000000000EB4000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameMeetingStarter.exe@ vs SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameMeetingStarter.exe@ vs SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engine Classification label: sus32.rans.winEXE@9/98@2/1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E14130 FindFirstFileW,RemoveDirectoryW,SetFileAttributesW,_strstr,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,GetLastError,FormatMessageW,WSAGetLastError, 0_2_00E14130
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E14F80 GetLastError,CreateToolhelp32Snapshot,GetLastError,Process32FirstW,CloseHandle,GetLastError,GetCurrentThread,OpenThreadToken,GetLastError,GetLastError,ImpersonateSelf,GetLastError,GetCurrentThread,OpenThreadToken,GetLastError,GetLastError,LookupPrivilegeValueW,AdjustTokenPrivileges,OpenProcess,OpenProcess,_strstr,TerminateProcess,CloseHandle,GetLastError,GetLastError,Process32NextW,CloseHandle, 0_2_00E14F80
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB5020 GetLastError,CreateToolhelp32Snapshot,GetLastError,Process32FirstW,CloseHandle,GetLastError,GetCurrentThread,OpenThreadToken,GetLastError,GetLastError,ImpersonateSelf,GetLastError,GetCurrentThread,OpenThreadToken,GetLastError,GetLastError,LookupPrivilegeValueW,AdjustTokenPrivileges,OpenProcess,OpenProcess,_strstr,TerminateProcess,FindCloseChangeNotification,GetLastError,GetLastError,Process32NextW,FindCloseChangeNotification, 4_2_00CB5020
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E14F80 GetLastError,CreateToolhelp32Snapshot,GetLastError,Process32FirstW,CloseHandle,GetLastError,GetCurrentThread,OpenThreadToken,GetLastError,GetLastError,ImpersonateSelf,GetLastError,GetCurrentThread,OpenThreadToken,GetLastError,GetLastError,LookupPrivilegeValueW,AdjustTokenPrivileges,OpenProcess,OpenProcess,_strstr,TerminateProcess,CloseHandle,GetLastError,GetLastError,Process32NextW,CloseHandle, 0_2_00E14F80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E2E860 CoInitialize,GetProcAddress,GetProcAddress,GetProcAddress,CoCreateInstance, 0_2_00E2E860
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E2B751 __ehhandler$?enable_segment@_Helper@_Concurrent_vector_base_v4@details@Concurrency@@SAIAAV234@II@Z,__EH_prolog3_catch,FindResourceW,LoadResource,LockResource,GetDesktopWindow,IsWindowEnabled,EnableWindow,EnableWindow,GetActiveWindow,SetActiveWindow,FreeResource, 0_2_00E2B751
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Mutant created: \Sessions\1\BaseNamedObjects\TMCacheFileMutex
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user~1\AppData\Local\Temp\TMSetup.txt Jump to behavior
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: TurboMeeting.exe, 00000006.00000002.3776134929.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001889000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
Source: TurboMeeting.exe, 00000006.00000002.3776134929.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001889000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: TurboMeeting.exe, 00000006.00000002.3776134929.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001889000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
Source: TurboMeeting.exe, 00000006.00000002.3776134929.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001889000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: TurboMeeting.exe, 00000006.00000002.3776134929.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001889000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: TurboMeeting.exe, 00000006.00000002.3776134929.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001889000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: TurboMeeting.exe, 00000006.00000002.3776134929.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001889000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Virustotal: Detection: 8%
Source: TMLauncher.exe String found in binary or memory: --installprinter
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File read: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe "C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe"
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe "C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe" --program C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\rsp1024hcmd.txt
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe TurboMeeting.exe --MagDetect
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe TurboMeeting.exe --VSEDetect
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe "C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe "C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe" --program C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\rsp1024hcmd.txt Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe TurboMeeting.exe --MagDetect Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe TurboMeeting.exe --VSEDetect Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: oledlg.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: oledlg.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: vdmdbg.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: msdmo.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: vistafunc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: d2d1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dlnashext.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wpdshext.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: asycfilt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: msftedit.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: windows.globalization.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: globinputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: windows.ui.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: windowmanagementapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: inputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: oledlg.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: vdmdbg.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: msdmo.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: vistafunc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: magnification.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: d3d9.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: oledlg.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: vdmdbg.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: msdmo.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: vistafunc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: magnification.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: d3d9.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32 Jump to behavior
Source: TurboMeeting.lnk.6.dr LNK file: ..\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe
Source: TurboMeeting Start Meeting.lnk.6.dr LNK file: ..\..\..\..\..\TurboMeeting\TurboMeeting\TurboMeeting.exe
Source: TurboMeeting Uninstall.lnk.6.dr LNK file: ..\..\..\..\..\TurboMeeting\TMRemover.exe
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File opened: C:\Users\user\Desktop\starter.cfg Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Automated click: Continue
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TurboMeeting Jump to behavior
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: certificate valid
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\RHUB2\PCSetup\Release.V2017\PCSetup.pdb source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000000.1308753930.0000000000E79000.00000002.00000001.01000000.00000003.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000002.1476961743.0000000000E79000.00000002.00000001.01000000.00000003.sdmp, TMLauncher.exe, 00000004.00000003.1469995904.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\TMResource\Release.V2017\TMResource.pdb source: TMLauncher.exe, 00000004.00000003.1471246256.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\PCInstaller\Release.V2017\PCInstaller.pdb source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500668690.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000003.1471056851.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000000.1422829262.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000002.1500863372.0000000000F36000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\PCUninstaller\Release.V2017\PCUninstaller.pdb@ source: TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\MyHookDll\Release.V2017\MyHookDll.pdb source: TurboMeeting.exe, 00000006.00000003.1499922106.00000000022EC000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1507007095.00000000006EB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: c:\dev\work\rhub\Code\SendSAS\release\SendSAS.pdb source: TMLauncher.exe, 00000004.00000003.1470318717.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\vistafunc\Release.V2017\vistafunc.pdb source: TMLauncher.exe, 00000004.00000003.1475416215.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000006.00000002.3778188999.000000006EC3D000.00000002.00000001.01000000.0000000A.sdmp, TurboMeeting.exe, 00000008.00000002.1527616968.000000006EC3D000.00000002.00000001.01000000.0000000A.sdmp, TurboMeeting.exe, 0000000B.00000002.1574382545.000000006EC3D000.00000002.00000001.01000000.0000000A.sdmp
Source: Binary string: C:\RHUB2\Code\PCUninstaller\Release.V2017\PCUninstaller.pdb source: TMLauncher.exe, 00000004.00000003.1471090996.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\TMService\Release.V2017\TMService.pdb source: TMLauncher.exe, 00000004.00000003.1471373053.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\TMService\Release.V2017\TMService.pdbM source: TMLauncher.exe, 00000004.00000003.1471373053.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\RHUB2\Code\PCGUI5\Release.V2017\TurboMeeting.pdb source: TurboMeeting.exe, 00000006.00000002.3776134929.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000000.1504992526.0000000001889000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 0000000B.00000000.1530054819.0000000001889000.00000002.00000001.01000000.00000009.sdmp
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: real checksum: 0xca6f3 should be: 0xcb5fb
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Static PE information: section name: _RDATA
Source: dbghelp.dll.0.dr Static PE information: section name: .didat
Source: InstallService.exe.0.dr Static PE information: section name: _RDATA
Source: PCStarter.exe.0.dr Static PE information: section name: _RDATA
Source: PCStarterXP.exe.0.dr Static PE information: section name: _RDATA
Source: TMDownloader.exe.0.dr Static PE information: section name: _RDATA
Source: TMInstaller.exe.0.dr Static PE information: section name: _RDATA
Source: TMRemover.exe.0.dr Static PE information: section name: _RDATA
Source: TMService.exe.0.dr Static PE information: section name: _RDATA
Source: TurboMeeting.dll.0.dr Static PE information: section name: .HookSha
Source: TurboMeeting.exe.0.dr Static PE information: section name: .rodata
Source: TurboMeeting.exe.0.dr Static PE information: section name: _RDATA
Source: TMLauncher.exe.0.dr Static PE information: section name: _RDATA
Source: TMRemover.exe.4.dr Static PE information: section name: _RDATA
Source: TMInstaller.exe.4.dr Static PE information: section name: _RDATA
Source: TMLauncher.exe.4.dr Static PE information: section name: _RDATA
Source: dbghelp.dll.4.dr Static PE information: section name: .didat
Source: InstallService.exe.4.dr Static PE information: section name: _RDATA
Source: PCStarter.exe.4.dr Static PE information: section name: _RDATA
Source: PCStarterXP.exe.4.dr Static PE information: section name: _RDATA
Source: TMDownloader.exe.4.dr Static PE information: section name: _RDATA
Source: TMInstaller.exe0.4.dr Static PE information: section name: _RDATA
Source: TMLauncher.exe0.4.dr Static PE information: section name: _RDATA
Source: TMRemover.exe0.4.dr Static PE information: section name: _RDATA
Source: TMService.exe.4.dr Static PE information: section name: _RDATA
Source: TurboMeeting.dll.4.dr Static PE information: section name: .HookSha
Source: TurboMeeting.exe.4.dr Static PE information: section name: .rodata
Source: TurboMeeting.exe.4.dr Static PE information: section name: _RDATA
Source: PCStarter.exe0.4.dr Static PE information: section name: _RDATA
Source: TM1713420902.dll.6.dr Static PE information: section name: .HookSha
Source: TM1713420903.dll.8.dr Static PE information: section name: .HookSha
Source: TM1713420905.dll.11.dr Static PE information: section name: .HookSha
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E44149 push ecx; ret 0_2_00E4415C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E448C6 push ecx; ret 0_2_00E448D9
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC0FE pushad ; ret 4_2_00CBC0FF
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE0AB pushad ; ret 4_2_00CBE0AC
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC0A6 pushad ; ret 4_2_00CBC0A7
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC04E pushad ; ret 4_2_00CBC04F
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE041 push dword ptr [ebx+60858D01h]; ret 4_2_00CBE054
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE15B pushad ; ret 4_2_00CBE15C
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC156 pushad ; ret 4_2_00CBC157
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE103 pushad ; ret 4_2_00CBE104
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC2D6 pushad ; ret 4_2_00CBC2D7
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE2BB pushad ; ret 4_2_00CBE2BC
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE263 pushad ; ret 4_2_00CBE264
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE20B pushad ; ret 4_2_00CBE20C
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC216 pushad ; ret 4_2_00CBC217
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC3EB pushad ; ret 4_2_00CBC3EC
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE3B3 push dword ptr [ebx+60858D01h]; ret 4_2_00CBE3C4
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE310 pushad ; ret 4_2_00CBE31A
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC32E pushad ; ret 4_2_00CBC32F
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC4F3 pushad ; ret 4_2_00CBC4F4
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC49B pushad ; ret 4_2_00CBC49C
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC443 pushad ; ret 4_2_00CBC444
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE463 push dword ptr [ebx+60858D01h]; ret 4_2_00CBE474
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBE414 push dword ptr [ebx+60858D01h]; ret 4_2_00CBE41C
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC5FB pushad ; ret 4_2_00CBC5FC
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC5A3 pushad ; ret 4_2_00CBC5A4
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC54B pushad ; ret 4_2_00CBC54C
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC6AB pushad ; ret 4_2_00CBC6AC
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC653 pushad ; ret 4_2_00CBC654
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC7FB push dword ptr [ebx+60858D01h]; ret 4_2_00CBC80C
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CBC7B3 pushad ; ret 4_2_00CBC7B4
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMDownloader.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMResource.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMRemover.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Sss.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMService.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TurboMeeting.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMLauncher.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\jsproxy.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\jsproxy.dll Jump to dropped file
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\HookDLL\TM1713420902.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\vistafunc.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\InstallService.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMService.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\PCStarter.exe Jump to dropped file
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\HookDLL\TM1713420903.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMRemover.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\dbghelp.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMInstaller.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMDownloader.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\dbghelp.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TMInstaller.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\PCStarter.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\Sss.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMInstaller.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\vistafunc.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\PCStarterXP.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\PCStarter.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMResource.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TMRemover.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\InstallService.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\PCStarterXP.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TurboMeeting.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TMLauncher.exe Jump to dropped file
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\HookDLL\TM1713420905.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe File created: C:\Users\user~1\AppData\Local\Temp\TMSetup.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File created: C:\Users\user~1\AppData\Local\Temp\TMInstaller.txt Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File created: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\setup_status.txt Jump to behavior

Boot Survival

barindex
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Window found: window name: Progman Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Window found: window name: Progman Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TurboMeeting Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TurboMeeting\TurboMeeting Start Meeting.lnk Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TurboMeeting\TurboMeeting Uninstall.lnk Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe File deleted: c:\users\user\desktop\securiteinfo.com.trojan.siggen21.62491.4036.26173.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E22DF3 IsIconic, 0_2_00E22DF3
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CD1882 IsIconic, 4_2_00CD1882
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E45F4A GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 0_2_00E45F4A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMDownloader.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMResource.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMRemover.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Sss.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMService.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\jsproxy.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\jsproxy.dll Jump to dropped file
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\HookDLL\TM1713420902.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\InstallService.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\PCStarter.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMService.exe Jump to dropped file
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\HookDLL\TM1713420903.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMRemover.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\dbghelp.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMDownloader.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\dbghelp.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\PCStarter.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\Sss.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\PCStarterXP.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\PCStarter.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TMResource.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TMRemover.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\InstallService.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\PCStarterXP.exe Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TurboMeeting.dll Jump to dropped file
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\HookDLL\TM1713420905.dll Jump to dropped file
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E14130 FindFirstFileW,RemoveDirectoryW,SetFileAttributesW,_strstr,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,GetLastError,FormatMessageW,WSAGetLastError, 0_2_00E14130
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E63648 FindFirstFileExW, 0_2_00E63648
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E338A9 __EH_prolog3_GS,GetFullPathNameW,PathIsUNCW,GetVolumeInformationW,CharUpperW,FindFirstFileW,FindClose, 0_2_00E338A9
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB4100 FindFirstFileW,RemoveDirectoryW,SetFileAttributesW,_strstr,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,GetLastError,FormatMessageW,WSAGetLastError, 4_2_00CB4100
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CB1F00 GetFileAttributesW,CreateDirectoryW,WSAGetLastError,FindFirstFileW,GetLastError,FormatMessageW,FindNextFileW,SetFileAttributesW,CopyFileW,GetLastError,FormatMessageW,FindNextFileW,FindClose, 4_2_00CB1F00
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CC9155 SetLastError,FindFirstFileW,GetLastError, 4_2_00CC9155
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CC929D GetModuleHandleW,GetProcAddress,FindFirstFileW, 4_2_00CC929D
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CD9D08 __EH_prolog3_GS,GetFullPathNameW,PathIsUNCW,GetVolumeInformationW,CharUpperW,FindFirstFileW,FindClose, 4_2_00CD9D08
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CFDEE5 FindFirstFileExW, 4_2_00CFDEE5
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Code function: 6_2_6EC354E6 FindFirstFileExW, 6_2_6EC354E6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E59389 VirtualQuery,GetSystemInfo,VirtualAlloc,VirtualProtect, 0_2_00E59389
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData\Roaming\TurboMeeting Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe File opened: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml Jump to behavior
Source: TurboMeeting.exe, 00000006.00000002.3776866345.0000000002263000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllA*k(
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476116809.000000000052B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476403815.00000000004BA000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000002.1476524588.00000000004BB000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW`mS%SystemRoot%\system32\mswsock.dllC
Source: TurboMeeting.exe, 0000000B.00000002.1554384401.00000000016C2000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: VMware Screen Codec / VMware Video
Source: TurboMeeting.exe, 00000008.00000003.1522178362.0000000000688000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 00000008.00000003.1521892122.000000000067D000.00000004.00000020.00020000.00000000.sdmp, TurboMeeting.exe, 0000000B.00000002.1555648025.0000000002267000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E18060 GetModuleFileNameW,lstrcpyW,lstrcpyW,lstrcpyW,lstrcpyW,CreateFileW,OutputDebugStringW,SetFilePointer,CloseHandle,lstrcpyW,CreateFileW,CloseHandle,IsDebuggerPresent, 0_2_00E18060
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E1D692 OutputDebugStringA,GetLastError, 0_2_00E1D692
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E59389 VirtualProtect ?,-00000001,00000104,?,?,?,0000001C 0_2_00E59389
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E5FD22 mov eax, dword ptr fs:[00000030h] 0_2_00E5FD22
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E4FDB8 mov eax, dword ptr fs:[00000030h] 0_2_00E4FDB8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E5FD67 mov eax, dword ptr fs:[00000030h] 0_2_00E5FD67
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CEE5E5 mov eax, dword ptr fs:[00000030h] 4_2_00CEE5E5
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CFAF97 mov eax, dword ptr fs:[00000030h] 4_2_00CFAF97
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Code function: 6_2_6EC33C4D mov eax, dword ptr fs:[00000030h] 6_2_6EC33C4D
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Code function: 6_2_6EC34DFD mov eax, dword ptr fs:[00000030h] 6_2_6EC34DFD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E633F8 GetProcessHeap, 0_2_00E633F8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E0E5A0 SetUnhandledExceptionFilter,SetThreadPriority,WSAGetLastError,SetEvent,SetEvent,SetEvent, 0_2_00E0E5A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E01596 SetUnhandledExceptionFilter,#17,_wprintf,GetClassInfoW,WSAStartup,GetModuleFileNameW,_strlen,_strlen,GetModuleFileNameW,PathStripPathW,_strstr,_strstr,_strlen,LoadImageW,SendMessageW,PostMessageW, 0_2_00E01596
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E4A64E IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00E4A64E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E44B9F IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00E44B9F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E44D32 SetUnhandledExceptionFilter, 0_2_00E44D32
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E43F3A SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_00E43F3A
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CA1C30 SetUnhandledExceptionFilter,#17,_strstr,_strstr, 4_2_00CA1C30
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CDE3BD SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 4_2_00CDE3BD
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CE4A2E IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 4_2_00CE4A2E
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CDEFB3 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 4_2_00CDEFB3
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CDF146 SetUnhandledExceptionFilter, 4_2_00CDF146
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Code function: 6_2_6EC34E2E IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 6_2_6EC34E2E
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Code function: 6_2_6EC32093 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 6_2_6EC32093
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Code function: 6_2_6EC31D02 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 6_2_6EC31D02
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E082A0 GetTempPathW,Sleep,CopyFileW,ShellExecuteExW,GetLastError,GetFileAttributesW, 0_2_00E082A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E13D20 GetCurrentProcess,OpenProcessToken,GetLastError,GetTokenInformation,GetTokenInformation,GetLastError,GetLastError,GlobalAlloc,GetTokenInformation,GetLastError,AllocateAndInitializeSid,GetLastError,EqualSid,FreeSid,GlobalFree, 0_2_00E13D20
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1309749293.00000000022EF000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: GShell_TrayWndkernel32.dllDbIU@0{@P
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500668690.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Shell_TrayWndkernel32.dllsClientName = %s, sDesktopDirectory = %s, sStartMenuDirectory = %s, sCurrentDirectory = %sc:\rhub2\code\pcutility\pcutility.cppPCUtility:RemoveLink()%s\%s.lnkRemove sLink: %sStart Session%s.lnkStart MeetingRemove start menu directory: %sSoftware\Microsoft\Windows\CurrentVersion\Uninstallfailed to remove registry, sKey = %s, error %d, %sPCUtility::RemoveLink()DeleteRegistryKey(%s)c:\ProgramData\Microsoft\Windows\Start Menu\Programs\%swSoftware\ClassesURL:%s StarterURL ProtocolsKey = %s, sURL = %s, sStarterFile = %s, sClientName = %sPCUtility:RegisterStarter()%s\shell\open\command"%s" %%1sCommandKey = %sSoftware\Microsoft\Internet Explorer\ProtocolExecute0WarnOnOpenRHUBMXmeetingvector<T> too longlist<T> too longMore than log instance, reported from MyLog::Initialize()Server.\RunServerLog%s%s.txt%s%s.bak%s%s.bak.bak%sServerMemoryLog.txt%sServerMemoryLog.bakrsp1024h%s.bak%s.bak.bak%sClientMemoryLog.txt%sClientMemoryLog.bakwfailed to create log file %s in MyLog::GetWorkingDirectory(), %dException happens in MyLog::Initialize()%d-%02d-%02d %02d:%02d:%02dafailed to create log file %s in MyLog::GetWorkingDirectory()%d
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000000.1308753930.0000000000E79000.00000002.00000001.01000000.00000003.sdmp, SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000002.1476961743.0000000000E79000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: Shell_TrayWndkernel32.dllDb
Source: TMLauncher.exe Binary or memory string: Progman
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: ?sBuffer is NULL = %s, iWidth = %d, iHeight = %dc:\rhub2\gui5\virtualgui\pcimage.cppPCImage::ImageBufferToPNGimage.GetLastError() = %sProgmanMS-SDIaMS-SDIbWindows.UI.Core.CoreWindow>>>>> New call c:\rhub2\gui5\virtualgui\pcapplicationsharingmonitor.cppPCApplicationSharingMonitor::GetApplicationList!!! ERROR: GetMonitorByHandle() failed for m_vWindowHandle = %dPCApplicationSharingMonitor::ChangeSharingApplicationc:\rhub2\gui5\virtualgui\guivideo.cppenter: m_iCurrentWebCamStatus = %d, iControlCode = %dGUIVideo::StopWebCamStopWebCam, iControlCode == PRESENTER_ALL_STOP || iControlCode == VIEWER_ALL_STOPGetWebCamNamesStopWebCamGUIVideo::WebCamStatusCallbackGUIVideo::WebCamStatusCallback.WebcamFailedToStartGUIVideo::WebCamStatusCallback.WebcamRefusedToStart1GUIVideo::WebCamStatusCallback.WebcamRefusedToStart2GUIVideo::WebCamStatusCallback.WebcamRefusedToStart3GUIVideo::WebCamStatusCallback.WebcamRefusedToStart4m_bWebcamStartedByUser = %sGUIVideo::SetWebcamStartedByUserm_bWebcamPreviewStartedByUser = %s
Source: SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe, 00000000.00000003.1476083142.00000000044F0000.00000004.00000020.00020000.00000000.sdmp, TMLauncher.exe, 00000004.00000002.1500668690.0000000000D10000.00000002.00000001.01000000.00000008.sdmp, TMLauncher.exe, 00000004.00000003.1491770470.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: invalid headerno new downloadhProcessSnap == INVALID_HANDLE_VALUE: %d, %s!Process32First(): %d, %ssProcessName = %sUtility::TerminateProcessByNameImpersonateSelf(SecurityImpersonation) failed: %d, %sOpenThreadToken() failed: %d, %sSeDebugPrivilegeCRITICAL ISSUE: there is a dead loop. One TurboMeeting.exe cannot be removed!.exesCommandLine = %s, sWorkingDirectory = %sUtility::StartProcessUTF8ToUTF16 is OKsucceeded.iErrorCode = %d, Error = %ssCommandLine = %sopenShellExecute(): iHinstance = %d, iErrorCode = %d, Error = %s, sExecutable = %s, sParameter = %s%s\*...Utility::RemoveAllFileEnd of RemoveAllFile: path = %s, %s, error code: %d, error: %s-sCurrentFilePath = %sSYSTEMbSystemUser = true, sUserApplicationDirectory = %s\..\..\..user application directory does not existbSystemUser = false, sUserApplicationDirectory = %sfrom CSIDL_COMMON_DOCUMENTS, sUserApplicationDirectory = %ssStartMenuDirectory = %ssCurrentDirectory = %ssCurrentFile = %ssUserApplicationDirectory = %ssTempDirectory = %ssDesktopDirectory = %sbUserAppDirAccessable = truebUserAppDirAccessable = falsebSystemUser = truebSystemUser = falseProgmanSHELLDLL_DefViewSysListView32sClientName: %s,
Source: TurboMeeting.exe, 00000006.00000000.1494408085.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000006.00000002.3776134929.00000000016C2000.00000002.00000001.01000000.00000009.sdmp, TurboMeeting.exe, 00000008.00000002.1524665016.00000000016C2000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: </__OUTLOOK_INTEGRATION__><__OUTLOOK_INTEGRATION__>outlook plugin was installed.c:\rhub2\pcgui5\pcgui\mainfrm.cppMainFrame::OnUpdateSoftwarePREVIOUS_ENTRY_POINT_JOINimage\ApplicationIcon.icoTurboMeetingMainWindowClassenter.MainFrame::OnClose()Error = %dToolbarWindow32TrayNotifyWndPCGUI.CSelectMeetingType::HostMeeting.SystemTrayIconTurboMeetingShell_TrayWnd</__ExitDueToNoConnection__><__ExitDueToNoConnection__></__Message__><__Message__></__PollingResponse__><__PollingResponse__>Received Polling response Error while parsing the string UserId = %d, %sMainWindow::OnRespondPolling()</__PollingId__><__PollingId__>Received Polling response Error while parsing the string No Poll Id UserId = %d, %sReceived Polling response from user But We do not have polling Id %dReceived Polling response UserId = %d, %s</__Choice0__><__Choice0__></__Choice1__><__Choice1__></__Choice2__><__Choice2__></__Choice3__><__Choice3__></__Choice4__><__Choice4__></__PollingQuestion__><__PollingQuestion__>Error while parsing the Polling Question %sMainWindow::OnShowRequestPolling()Error while parsing the Polling id %s</__IsSingleResponse__><__IsSingleResponse__></__Question__><__Question__></__PollingResult__><__PollingResult__>Error while parsing the Polling results From User %d : %sMainWindow::OnShowPublishPolling()Error while parsing the Polling Id. No PollingId is present: From User %d : %s</__TotalResponse__><__TotalResponse__></__ResponseChoice0__><__ResponseChoice0__></__ResponseChoice1__><__ResponseChoice1__></__ResponseChoice2__><__ResponseChoice2__></__ResponseChoice3__><__ResponseChoice3__></__ResponseChoice4__><__ResponseChoice4__>PCGUI.MainWindow::MainWindow.ExitPCGUI.IDR_TRAY_MENU.ID_OPENPCGUI.IDD_ACTIVEGIALOG.IDC_STATIC_ACTIVE_LIST_HEADINGPCGUI.CScreenShare::UpdateAttendeeList.HostPCGUI.PLoginDialog::OnInitDialog.JoinPCGUI.MainWindow::MainWindow.AboutPCGUI.BUTTON.REMOVEOpenATTENDEE_CONTROL_DIALOG User Type: %d, iChangedUserType = %dMainFrame::UpdateGUIOnUserTypeHOST_CONTROL_DIALOG User Type: %dMainFrame::UpdateGUIOnUserType.HOST_BECOME_VIEWERMainFrame::UpdateGUIOnUserType.HOST_BECOME_PRESENTERATTENDEE_CONTROL_DIALOG User Type: %dMainFrame::UpdateGUIOnUserType.ATTENDEE_BECOME_VIEWERMainFrame::UpdateGUIOnUserType.ATTENDEE_BECOME_PRESENTERMainFrame::UpdateGUIOnUserType.ATTENDEE_BECOME_HOSTMainFrame::UpdateGUIOnUserType.HOST_BECOME_ATTENDEEPCGUI.PhysicalGUI::ProcessMessage.WantControllerPermissionPCGUI.PhysicalGUI::ProcessMessage.RequestControllerPCGUI.PhysicalGUI::ProcessMessage.WantPresenterPermissionPCGUI.PhysicalGUI::ProcessMessage.RequestPresenteriCameraDisplayFormat = %d, iUserType = %d m_bVideoDetached = %d, m_bNoWebcamAvailable = %dMainFrame::OnUpdateWindowPositionTurboMeeting.exeCMD_BYPASS_PRESENCE: sCommand = %sMainFrame::ExecuteCommand()Failed CMD_BYPASS_PRESENCE. sCommand = %sPCGUI.IDD_ASSIGN_PRESENTER_DIALOG.WindowTextPCApplicationSharingMonitor::GetApplicationList.StayWithHDPCGUI.PControlPanelWnd::CreateButtonControls.BecomePresenterPCGUI.PSliderDialo
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E44DDF cpuid 0_2_00E44DDF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: GetModuleHandleW,GetProcAddress,EncodePointer,DecodePointer,GetLocaleInfoEx,GetLocaleInfoW, 0_2_00E2F81B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, 0_2_00E66014
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: GetLocaleInfoW, 0_2_00E66264
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, 0_2_00E6638D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: GetLocaleInfoW, 0_2_00E66494
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, 0_2_00E66567
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: EnumSystemLocalesW, 0_2_00E5D13C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: GetLocaleInfoW, 0_2_00E5D78F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, 0_2_00E65C29
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: EnumSystemLocalesW, 0_2_00E65EEC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: EnumSystemLocalesW, 0_2_00E65EA1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: EnumSystemLocalesW, 0_2_00E65F87
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: GetModuleHandleW,GetProcAddress,EncodePointer,DecodePointer,GetLocaleInfoEx,GetLocaleInfoW, 4_2_00CD5FAF
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: GetACP,IsValidCodePage,GetLocaleInfoW, 4_2_00D0051B
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: EnumSystemLocalesW, 4_2_00D007BD
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: EnumSystemLocalesW, 4_2_00D008A3
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: EnumSystemLocalesW, 4_2_00D00808
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, 4_2_00D0092E
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: GetLocaleInfoW, 4_2_00D00B81
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, 4_2_00D00CA7
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: GetLocaleInfoW, 4_2_00D00DAD
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, 4_2_00D00E7C
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: EnumSystemLocalesW, 4_2_00CF7731
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: GetLocaleInfoW, 4_2_00CF7C53
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMSetup.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\tm_starter_dir\rsp1024hcmd.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Queries volume information: C:\Users\user\AppData\Local\Temp\TMInstaller.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\rsp1024hcmd.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\rsp1024h.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\MagDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Configure.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\Cache.xml VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\TurboMeeting\TurboMeeting\TurboMeeting.exe Queries volume information: C:\Users\user\AppData\Local\Temp\SVEDetector.txt VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E12320 GetSystemTime, 0_2_00E12320
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E13110 GetModuleFileNameW,GetLongPathNameW,GetUserNameW,SHGetFolderPathW,_strstr,_strstr,SHGetFolderPathW,SHGetFolderPathW,GetTempPathW,GetLongPathNameW,SHGetSpecialFolderPathW,SHGetFolderPathW,GetLongPathNameW,GetLongPathNameW,SHGetFolderPathW,GetLongPathNameW, 0_2_00E13110
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E62425 _free,_free,_free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,_free, 0_2_00E62425
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Siggen21.62491.4036.26173.exe Code function: 0_2_00E172E0 GetVersionExW,GetVersionExW,GetVersionExW,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,lstrcmpiW,lstrcmpiW,lstrcmpiW,lstrcmpiW, 0_2_00E172E0
Source: C:\Users\user\AppData\Local\Temp\tm_starter_dir\TMLauncher.exe Code function: 4_2_00CA1840 __ehhandler$??1_Scoped_lock@?$SafeRWList@UListEntry@details@Concurrency@@VNoCount@CollectionTypes@23@V_ReaderWriterLock@23@@details@Concurrency@@QAE@XZ, 4_2_00CA1840
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs