Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\TSRDDF1.tmp |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\TSRDE12.tmp |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8 |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\twux.exe._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\WebView2Loader.dll._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\pop8query.exe._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\WebView2Loader.dll._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: urlmon.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: wininet.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: iertutil.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: srvcli.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: netutils.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: version.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: version.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: sfc.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: sfc_os.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: kernel.appcore.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: sxs.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: mscoree.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: vcruntime140_clr0400.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: ucrtbase_clr0400.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: rstrtmgr.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: ncrypt.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: ntasn1.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: textinputframework.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: coreuicomponents.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: coremessaging.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: ntmarta.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: textshaping.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: sspicli.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: userenv.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: profapi.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: msftedit.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: windows.storage.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: wldp.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: profapi.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: windows.globalization.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: bcp47langs.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: bcp47mrm.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: globinputhost.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: dataexchange.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: d3d11.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: dcomp.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: dxgi.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: twinapi.appcore.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: sxs.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: mscoree.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: sxs.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: mscoree.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: propsys.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: linkinfo.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: ntshrui.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: cscapi.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: sxs.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: mscoree.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: onecorecommonproxystub.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: dxcore.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Section loaded: netutils.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: userenv.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: version.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: wininet.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: kernel.appcore.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: uxtheme.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: windows.storage.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: wldp.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: textshaping.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: windowscodecs.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: textinputframework.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: coreuicomponents.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: coremessaging.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: ntmarta.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: wintypes.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: wintypes.dll |
Source: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe |
Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\TSRDDF1.tmp |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\TSRDE12.tmp |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8 |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\twux.exe._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\WebView2Loader.dll._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\pop8query.exe._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Directory created: C:\Program Files\Harzing's Publish or Perish 8\WebView2Loader.dll._tm |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
File created: C:\Program Files\Harzing's Publish or Perish 8\WebView2Loader.dll._tm |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
File created: C:\Users\user\AppData\Local\Temp\36071EAE\_Setup.dll |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
File created: C:\ProgramData\Uninstall\{D7808C1C-93A9-4369-8385-A789888ED9D7}\x86\regsvr32.exe |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
File created: C:\Users\user\AppData\Local\Temp\Tsu8BBD8215.dll |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
File created: C:\Users\user\AppData\Local\Temp\36071EAE\Setup.exe |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
File created: C:\Program Files\Harzing's Publish or Perish 8\pop8win.exe._tm |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
File created: C:\ProgramData\Uninstall\{D7808C1C-93A9-4369-8385-A789888ED9D7}\x64\regsvr32.exe |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
File created: C:\Program Files\Harzing's Publish or Perish 8\twux.exe._tm |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
File created: C:\Program Files\Harzing's Publish or Perish 8\pop8query.exe._tm |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Dropped PE file which has not been started: C:\Program Files\Harzing's Publish or Perish 8\WebView2Loader.dll._tm |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\36071EAE\_Setup.dll |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Dropped PE file which has not been started: C:\ProgramData\Uninstall\{D7808C1C-93A9-4369-8385-A789888ED9D7}\x86\regsvr32.exe |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Tsu8BBD8215.dll |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\36071EAE\Setup.exe |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Dropped PE file which has not been started: C:\ProgramData\Uninstall\{D7808C1C-93A9-4369-8385-A789888ED9D7}\x64\regsvr32.exe |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Dropped PE file which has not been started: C:\Program Files\Harzing's Publish or Perish 8\twux.exe._tm |
Jump to dropped file |
Source: C:\Users\user\Desktop\PoP8Setup.exe |
Dropped PE file which has not been started: C:\Program Files\Harzing's Publish or Perish 8\pop8query.exe._tm |
Jump to dropped file |