Windows Analysis Report
SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe

Overview

General Information

Sample name: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe
Analysis ID: 1431909
MD5: 860cf1e911539c2afdd5f8e9bc4ca6b4
SHA1: dc4801507a6bf3879f9f4f0aad0b4fc1fa4a8166
SHA256: b421c7df00a72af8b170345a3872ab637274eda790f2ce8f93a5416a82bff8f0
Infos:

Detection

Score: 17
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Signatures

PE file has a writeable .text section
Abnormal high CPU Usage
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to simulate mouse events
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Entry point lies outside standard sections
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Installs a global mouse hook
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sleep loop found (likely to delay execution)
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses taskkill to terminate processes

Classification

Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Static PE information: certificate valid
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: msvcr70.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006C44000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000002.2393579012.000000007C039000.00000002.00000001.01000000.0000000C.sdmp, is-NQJJK.tmp.1.dr
Source: Binary string: c:\cvs_sandbox\SteadyMouse\MouseConfig\Release\MouseConfig.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.000000000690D000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000000.1359812129.000000000040A000.00000002.00000001.01000000.0000000A.sdmp, is-MDLV9.tmp.1.dr
Source: Binary string: gdiplus.pdbv+ source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069B7000.00000004.00001000.00020000.00000000.sdmp, is-QGVNR.tmp.1.dr
Source: Binary string: msvcr71.pdb< source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006C91000.00000004.00001000.00020000.00000000.sdmp, is-96DUB.tmp.1.dr
Source: Binary string: c:\cvs_sandbox\SteadyMouse\MouseHook\Release\MouseHook.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069A8000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000002.2393256945.0000000010009000.00000002.00000001.01000000.0000000B.sdmp, is-I44SO.tmp.1.dr, is-DIJ9B.tmp.1.dr
Source: Binary string: shfolder.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006CE6000.00000004.00001000.00020000.00000000.sdmp, is-LBDD3.tmp.1.dr
Source: Binary string: c:\cvs_sandbox\SteadyMouse\MouseHook\Release\MouseHook.pdbd source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069A8000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000002.2393256945.0000000010009000.00000002.00000001.01000000.0000000B.sdmp, is-I44SO.tmp.1.dr, is-DIJ9B.tmp.1.dr
Source: Binary string: shfolder.pdb@ source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006CE6000.00000004.00001000.00020000.00000000.sdmp, is-LBDD3.tmp.1.dr
Source: Binary string: gdiplus.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069B7000.00000004.00001000.00020000.00000000.sdmp, is-QGVNR.tmp.1.dr
Source: Binary string: MFC70.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069B7000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000002.2393776821.000000007C141000.00000020.00000001.01000000.0000000D.sdmp, is-JA7DK.tmp.1.dr
Source: Binary string: msvcr71.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006C91000.00000004.00001000.00020000.00000000.sdmp, is-96DUB.tmp.1.dr
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C016C52 _stat64,_mbspbrk,_errno,__doserrno,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileA,_mbspbrk,_fullpath,strlen,GetDriveTypeA,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C016C52
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C009D87 malloc,FindClose,FindFirstFileW,FindNextFileW,FindClose, 30_2_7C009D87
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C015DA9 _wfindfirst,FindFirstFileW,GetLastError,_errno,_errno,_errno,wcscpy, 30_2_7C015DA9
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C017E1B _wstati64,wcspbrk,_errno,__doserrno,_errno,__doserrno,towlower,_getdrive,FindFirstFileW,wcspbrk,_wfullpath,wcslen,GetDriveTypeW,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C017E1B
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C015F6A _wfindfirst64,FindFirstFileW,GetLastError,_errno,_errno,_errno,wcscpy, 30_2_7C015F6A
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C016F7D _stati64,_mbspbrk,_errno,__doserrno,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileA,_mbspbrk,_fullpath,strlen,GetDriveTypeA,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C016F7D
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C009899 malloc,FindClose,FindFirstFileA,FindNextFileA,FindClose, 30_2_7C009899
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C016901 _stat,_mbspbrk,_errno,__doserrno,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileA,_mbspbrk,_fullpath,strlen,GetDriveTypeA,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C016901
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C01592E _findfirst64,FindFirstFileA,GetLastError,_errno,_errno,_errno,strcpy, 30_2_7C01592E
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C017A60 _wstat64,wcspbrk,_errno,__doserrno,_errno,__doserrno,towlower,_getdrive,FindFirstFileW,wcspbrk,_wfullpath,wcslen,GetDriveTypeW,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C017A60
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C015B43 _findfirsti64,FindFirstFileA,GetLastError,_errno,_errno,_errno,strcpy, 30_2_7C015B43
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C015707 _findfirst,FindFirstFileA,GetLastError,_errno,_errno,_errno,strcpy, 30_2_7C015707
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C017777 _wstat,wcspbrk,_errno,__doserrno,_errno,__doserrno,towlower,_getdrive,FindFirstFileW,wcspbrk,_wfullpath,wcslen,GetDriveTypeW,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C017777
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C01617F _wfindfirsti64,FindFirstFileW,GetLastError,_errno,_errno,_errno,wcscpy, 30_2_7C01617F
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.000000000244C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: %https://www.facebook.com/steadymouse/! equals www.facebook.com (Facebook)
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: R{group}\Community\SteadyMouse on FacebookJhttps://www.facebook.com/steadymouse/( equals www.facebook.com (Facebook)
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.00000000023BB000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse on Facebook.url.1.dr String found in binary or memory: URL=https://www.facebook.com/steadymouse/ equals www.facebook.com (Facebook)
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1138830761.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1369733416.0000000002888000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1364769379.000000000365D000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://counter-strike.com.ua/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, is-MDLV9.tmp.1.dr, is-I44SO.tmp.1.dr, is-3HOGA.tmp.1.dr, is-DIJ9B.tmp.1.dr, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp.0.dr String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, is-MDLV9.tmp.1.dr, is-I44SO.tmp.1.dr, is-3HOGA.tmp.1.dr, is-DIJ9B.tmp.1.dr, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp.0.dr String found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp.0.dr String found in binary or memory: http://ocsp.comodoca.com0
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1370199338.0000000002293000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1138830761.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1364769379.000000000365D000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dk-soft.org/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1370199338.0000000002293000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1138830761.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.0000000002330000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.haysoft.org%1-k
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1139734999.000000007FCC0000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1139457880.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000000.1140656079.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-3HOGA.tmp.1.dr, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp.0.dr String found in binary or memory: http://www.innosetup.com/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1370199338.0000000002293000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1138830761.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.0000000002330000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.palkornel.hu/innosetup%1
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1139734999.000000007FCC0000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1139457880.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000000.1140656079.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-3HOGA.tmp.1.dr, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp.0.dr String found in binary or memory: http://www.remobjects.com/ps
Source: is-MDLV9.tmp.1.dr String found in binary or memory: http://www.steadymouse.com/donations/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.000000000245A000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1364769379.0000000003637000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse on Keybase.url.1.dr String found in binary or memory: https://keybase.io/steadymouse
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://keybase.io/steadymouse(
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.000000000245A000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse on Twitter.url.1.dr String found in binary or memory: https://twitter.com/steadymouse
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://twitter.com/steadymouse(
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.000000000244C000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse on Instagram.url.1.dr String found in binary or memory: https://www.instagram.com/steadymouse/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.instagram.com/steadymouse/(
Source: SteadyMouse on Product Hunt.url.1.dr String found in binary or memory: https://www.producthunt.com/posts/steadymouse
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.producthunt.com/posts/steadymouse(
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.00000000023F5000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.producthunt.com/posts/steadymouseq
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.000000000244C000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse on Reddit.url.1.dr String found in binary or memory: https://www.reddit.com/r/steadymouse/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.reddit.com/r/steadymouse/(
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1138830761.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1370199338.0000000002343000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006CE6000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.00000000023AC000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1364769379.00000000035D6000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1366558728.0000000000828000.00000004.00000020.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000002.1367404811.000000000018E000.00000004.00000010.00020000.00000000.sdmp, notepad.exe, 0000001D.00000002.2390484285.0000000000798000.00000004.00000020.00020000.00000000.sdmp, is-M4DE7.tmp.1.dr String found in binary or memory: https://www.steadymouse.com
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.000000000245A000.00000004.00001000.00020000.00000000.sdmp, View Website.url.1.dr String found in binary or memory: https://www.steadymouse.com/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.steadymouse.com/(
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1138830761.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.steadymouse.com/8https://www.steadymouse.com/8https://www.steadymouse.com/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1138830761.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1370199338.0000000002343000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.00000000023AC000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1364769379.00000000035D6000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1366558728.0000000000828000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.steadymouse.com/purchase/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.00000000023F5000.00000004.00001000.00020000.00000000.sdmp, Purchase Full Version.url.1.dr String found in binary or memory: https://www.steadymouse.com/purchase/#buynow
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.steadymouse.com/purchase/#buynow(
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1370199338.00000000023BA000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.000000000245A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.steadymouse.com/q
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1138830761.0000000002550000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1370199338.0000000002343000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1141581852.0000000003360000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1365559029.00000000023AC000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1364769379.00000000035D6000.00000004.00001000.00020000.00000000.sdmp, SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1366558728.0000000000828000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.steadymouse.com/troubleshooting/
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069B7000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: DirectDrawCreateEx memstr_d0d77858-0
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Windows user hook set: 0 mouse low level C:\Program Files (x86)\SteadyMouse\MouseHook.dll Jump to behavior

System Summary

barindex
Source: is-QGVNR.tmp.1.dr Static PE information: Section: .text IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Process Stats: CPU usage > 24%
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_10004970 30_2_10004970
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C006C99 30_2_7C006C99
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C035CD8 30_2_7C035CD8
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C034E52 30_2_7C034E52
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C019F26 30_2_7C019F26
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C0339D1 30_2_7C0339D1
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C027B5F 30_2_7C027B5F
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C003B8A 30_2_7C003B8A
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C01C432 30_2_7C01C432
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C032715 30_2_7C032715
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C00A72B 30_2_7C00A72B
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: String function: 7C001000 appears 160 times
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: String function: 7C00F4BB appears 38 times
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: String function: 7C0097E1 appears 89 times
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: String function: 7C0011D9 appears 52 times
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-3HOGA.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-3HOGA.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1139457880.00000000026CB000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe, 00000000.00000003.1139734999.000000007FE37000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: is-QGVNR.tmp.1.dr Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
Source: is-QGVNR.tmp.1.dr Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESERVED size: 0x100000 address: 0x0
Source: is-QGVNR.tmp.1.dr Static PE information: Section: .rsrc ZLIB complexity 0.9983176051980198
Source: is-QGVNR.tmp.1.dr Static PE information: Section: .reloc ZLIB complexity 0.9897203947368421
Source: classification engine Classification label: clean17.evad.winEXE@31/47@0/0
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C015D46 _getdiskfree,GetDiskFreeSpaceA,GetLastError, 30_2_7C015D46
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Users\user\AppData\Local\Programs Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4896:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1608:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6220:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5156:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4868:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1036:120:WilError_03
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\MouseHookSynchronizationMutex
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Mutant created: \Sessions\1\BaseNamedObjects\Global\SetupSteadyMouseMutex
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6428:120:WilError_03
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\SteadyMouse.exe
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6360:120:WilError_03
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe File created: C:\Users\user\AppData\Local\Temp\is-03N37.tmp Jump to behavior
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;SteadyMouse.exe&quot;)
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;SteadyMouse.exe&quot;)
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;SteadyMouse.exe&quot;)
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;SteadyMouse.exe&quot;)
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;SteadyMouse.exe&quot;)
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;SteadyMouse.exe&quot;)
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;SteadyMouse.exe&quot;)
Source: C:\Windows\SysWOW64\taskkill.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;SteadyMouse.exe&quot;)
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe String found in binary or memory: /LOADINF="filename"
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe File read: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe "C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe"
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Process created: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp "C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp" /SL5="$30324,2152528,535552,C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe"
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im SteadyMouse.exe
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im SteadyMouse.exe
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe
Source: C:\Windows\SysWOW64\taskkill.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\notepad.exe "C:\Windows\system32\NOTEPAD.EXE" C:\Program Files (x86)\SteadyMouse\README.txt
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe "C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe"
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Process created: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp "C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp" /SL5="$30324,2152528,535552,C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\notepad.exe "C:\Windows\system32\NOTEPAD.EXE" C:\Program Files (x86)\SteadyMouse\README.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe "C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe" Jump to behavior
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: msftedit.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: windows.globalization.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: globinputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: windows.ui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: windowmanagementapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: inputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: policymanager.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: mrmcorer.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: efswrt.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: mousehook.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: msvcr70.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: mfc70.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: mfc70eng.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: mfc70enu.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: mfc70eng.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: mfc70enu.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: mfc70loc.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5E5F29CE-E0A8-49D3-AF32-7A7BDC173478}\InProcServer32 Jump to behavior
Source: View ReadMe.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\SteadyMouse\README.txt
Source: View License Agreement.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\SteadyMouse\LICENSE.txt
Source: SteadyMouse.lnk.1.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\SteadyMouse\SteadyMouse.exe
Source: SteadyMouse.lnk0.1.dr LNK file: ..\..\..\..\..\Program Files (x86)\SteadyMouse\SteadyMouse.exe
Source: SteadyMouse.lnk1.1.dr LNK file: ..\..\..\Program Files (x86)\SteadyMouse\SteadyMouse.exe
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe File written: C:\Users\user\AppData\Roaming\SteadyMouse\settings.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Window found: window name: TSelectLanguageForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Window detected: Number of UI elements: 19
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Static PE information: certificate valid
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Static file information: File size 2772888 > 1048576
Source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: msvcr70.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006C44000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000002.2393579012.000000007C039000.00000002.00000001.01000000.0000000C.sdmp, is-NQJJK.tmp.1.dr
Source: Binary string: c:\cvs_sandbox\SteadyMouse\MouseConfig\Release\MouseConfig.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.000000000690D000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000000.1359812129.000000000040A000.00000002.00000001.01000000.0000000A.sdmp, is-MDLV9.tmp.1.dr
Source: Binary string: gdiplus.pdbv+ source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069B7000.00000004.00001000.00020000.00000000.sdmp, is-QGVNR.tmp.1.dr
Source: Binary string: msvcr71.pdb< source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006C91000.00000004.00001000.00020000.00000000.sdmp, is-96DUB.tmp.1.dr
Source: Binary string: c:\cvs_sandbox\SteadyMouse\MouseHook\Release\MouseHook.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069A8000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000002.2393256945.0000000010009000.00000002.00000001.01000000.0000000B.sdmp, is-I44SO.tmp.1.dr, is-DIJ9B.tmp.1.dr
Source: Binary string: shfolder.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006CE6000.00000004.00001000.00020000.00000000.sdmp, is-LBDD3.tmp.1.dr
Source: Binary string: c:\cvs_sandbox\SteadyMouse\MouseHook\Release\MouseHook.pdbd source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069A8000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000002.2393256945.0000000010009000.00000002.00000001.01000000.0000000B.sdmp, is-I44SO.tmp.1.dr, is-DIJ9B.tmp.1.dr
Source: Binary string: shfolder.pdb@ source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006CE6000.00000004.00001000.00020000.00000000.sdmp, is-LBDD3.tmp.1.dr
Source: Binary string: gdiplus.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069B7000.00000004.00001000.00020000.00000000.sdmp, is-QGVNR.tmp.1.dr
Source: Binary string: MFC70.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.00000000069B7000.00000004.00001000.00020000.00000000.sdmp, SteadyMouse.exe, 0000001E.00000002.2393776821.000000007C141000.00000020.00000001.01000000.0000000D.sdmp, is-JA7DK.tmp.1.dr
Source: Binary string: msvcr71.pdb source: SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp, 00000001.00000003.1360715363.0000000006C91000.00000004.00001000.00020000.00000000.sdmp, is-96DUB.tmp.1.dr
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_100053FD LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 30_2_100053FD
Source: initial sample Static PE information: section where entry point is pointing to: .aspack
Source: is-QGVNR.tmp.1.dr Static PE information: real checksum: 0x1a18da should be: 0x192dc7
Source: is-QGVNR.tmp.1.dr Static PE information: section name: Shared
Source: is-QGVNR.tmp.1.dr Static PE information: section name: .aspack
Source: is-QGVNR.tmp.1.dr Static PE information: section name: .adata
Source: is-I44SO.tmp.1.dr Static PE information: section name: .local
Source: is-I44SO.tmp.1.dr Static PE information: section name: .shared
Source: is-DIJ9B.tmp.1.dr Static PE information: section name: .local
Source: is-DIJ9B.tmp.1.dr Static PE information: section name: .shared
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_10004417 push ecx; ret 30_2_10004427
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_10002B90 push eax; ret 30_2_10002BA4
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_10002B90 push eax; ret 30_2_10002BCC
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C001C3A push eax; ret 30_2_7C001C4E
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C001C3A push eax; ret 30_2_7C001C76
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C003828 push eax; ret 30_2_7C003846
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C00103B push ecx; ret 30_2_7C00104B
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\is-3HOGA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\is-MDLV9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\shfolder.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\is-QGVNR.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\is-JA7DK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\MouseHook.dll (copy) Jump to dropped file
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe File created: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\is-DIJ9B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\msvcr71.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\is-I44SO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\is-96DUB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\gdiplus.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\mfc70.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\is-LBDD3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Users\user\AppData\Local\Temp\is-QMRKV.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\is-NQJJK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\Program Files (x86)\SteadyMouse\msvcr70.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\Community Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\Community\SteadyMouse on Reddit.url Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\Community\SteadyMouse on Twitter.url Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\Community\SteadyMouse on Facebook.url Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\Community\SteadyMouse on Instagram.url Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\Community\SteadyMouse on Product Hunt.url Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\Community\SteadyMouse on Keybase.url Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\View ReadMe.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\View License Agreement.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\View Website.url Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\Purchase Full Version.url Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse\SteadyMouse.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteadyMouse.lnk Jump to behavior
Source: C:\Users\user\Desktop\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Window / User API: threadDelayed 6194 Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Window / User API: threadDelayed 729 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Program Files (x86)\SteadyMouse\is-QGVNR.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Program Files (x86)\SteadyMouse\is-JA7DK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Program Files (x86)\SteadyMouse\is-DIJ9B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Program Files (x86)\SteadyMouse\msvcr71.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Program Files (x86)\SteadyMouse\is-96DUB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Program Files (x86)\SteadyMouse\is-I44SO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Program Files (x86)\SteadyMouse\gdiplus.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Program Files (x86)\SteadyMouse\is-LBDD3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-QMRKV.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Dropped PE file which has not been started: C:\Program Files (x86)\SteadyMouse\is-NQJJK.tmp Jump to dropped file
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe API coverage: 1.5 %
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe TID: 6152 Thread sleep time: -61940s >= -30000s Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe TID: 5876 Thread sleep time: -145800s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809 Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Last function: Thread delayed
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Thread sleep count: Count: 6194 delay: -10 Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C016C52 _stat64,_mbspbrk,_errno,__doserrno,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileA,_mbspbrk,_fullpath,strlen,GetDriveTypeA,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C016C52
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C009D87 malloc,FindClose,FindFirstFileW,FindNextFileW,FindClose, 30_2_7C009D87
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C015DA9 _wfindfirst,FindFirstFileW,GetLastError,_errno,_errno,_errno,wcscpy, 30_2_7C015DA9
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C017E1B _wstati64,wcspbrk,_errno,__doserrno,_errno,__doserrno,towlower,_getdrive,FindFirstFileW,wcspbrk,_wfullpath,wcslen,GetDriveTypeW,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C017E1B
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C015F6A _wfindfirst64,FindFirstFileW,GetLastError,_errno,_errno,_errno,wcscpy, 30_2_7C015F6A
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C016F7D _stati64,_mbspbrk,_errno,__doserrno,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileA,_mbspbrk,_fullpath,strlen,GetDriveTypeA,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C016F7D
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C009899 malloc,FindClose,FindFirstFileA,FindNextFileA,FindClose, 30_2_7C009899
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C016901 _stat,_mbspbrk,_errno,__doserrno,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileA,_mbspbrk,_fullpath,strlen,GetDriveTypeA,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C016901
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C01592E _findfirst64,FindFirstFileA,GetLastError,_errno,_errno,_errno,strcpy, 30_2_7C01592E
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C017A60 _wstat64,wcspbrk,_errno,__doserrno,_errno,__doserrno,towlower,_getdrive,FindFirstFileW,wcspbrk,_wfullpath,wcslen,GetDriveTypeW,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C017A60
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C015B43 _findfirsti64,FindFirstFileA,GetLastError,_errno,_errno,_errno,strcpy, 30_2_7C015B43
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C015707 _findfirst,FindFirstFileA,GetLastError,_errno,_errno,_errno,strcpy, 30_2_7C015707
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C017777 _wstat,wcspbrk,_errno,__doserrno,_errno,__doserrno,towlower,_getdrive,FindFirstFileW,wcspbrk,_wfullpath,wcslen,GetDriveTypeW,_errno,__doserrno,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, 30_2_7C017777
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C01617F _wfindfirsti64,FindFirstFileW,GetLastError,_errno,_errno,_errno,wcscpy, 30_2_7C01617F
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_10007148 VirtualQuery,GetSystemInfo,VirtualQuery,VirtualAlloc,VirtualProtect, 30_2_10007148
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process information queried: ProcessInformation Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_100053FD LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 30_2_100053FD
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\taskkill.exe Process token adjusted: Debug Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_10001200 _MouseHook@12,CallNextHookEx,WaitForSingleObject,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,?MouseLeftButton@@3UMOUSE_BUTTON_EVENT@@A,?MouseLeftButton@@3UMOUSE_BUTTON_EVENT@@A,?MouseLeftButton@@3UMOUSE_BUTTON_EVENT@@A,GetMessageExtraInfo,GetMessageExtraInfo,mouse_event,mouse_event,GetMessageExtraInfo,mouse_event,?MouseMiddleButton@@3UMOUSE_BUTTON_EVENT@@A,?MouseMiddleButton@@3UMOUSE_BUTTON_EVENT@@A,?MouseMiddleButton@@3UMOUSE_BUTTON_EVENT@@A,GetMessageExtraInfo,GetMessageExtraInfo,mouse_event,mouse_event,GetMessageExtraInfo,mouse_event,?MouseRightButton@@3UMOUSE_BUTTON_EVENT@@A,?MouseRightButton@@3UMOUSE_BUTTON_EVENT@@A,?MouseRightButton@@3UMOUSE_BUTTON_EVENT@@A,GetMessageExtraInfo,GetMessageExtraInfo,mouse_event,mouse_event,GetMessageExtraInfo,mouse_event,ReleaseMutex,CallNextHookEx, 30_2_10001200
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\notepad.exe "C:\Windows\system32\NOTEPAD.EXE" C:\Program Files (x86)\SteadyMouse\README.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe "C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /f /im SteadyMouse.exe Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C002319 cpuid 30_2_7C002319
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: GetLocaleInfoA, 30_2_10006F30
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: strlen,EnumSystemLocalesA, 30_2_7C00EC0C
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: strlen,strlen,EnumSystemLocalesA, 30_2_7C00EC43
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: strlen,EnumSystemLocalesA, 30_2_7C00ECC9
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: GetLocaleInfoA,_TranslateName,_TranslateName,IsValidCodePage,IsValidLocale,strcpy,_itoa, 30_2_7C00ED1E
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: GetLocaleInfoA,atol, 30_2_7C00EED3
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: GetLocaleInfoA,_strncpy, 30_2_7C00E6D5
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: GetLastError,malloc,malloc,free,_strncpy,free,__crtGetLocaleInfoW,isdigit, 30_2_7C00F0EB
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: __crtGetLocaleInfoW,GetLocaleInfoW,GetLastError,GetLocaleInfoW,GetLocaleInfoA,malloc,GetLocaleInfoA,MultiByteToWideChar,free, 30_2_7C00F21C
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: _resetstkoflw,malloc,GetLocaleInfoA,MultiByteToWideChar,free, 30_2_7C00F2D8
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: GetLocaleInfoW,GetLastError,GetLocaleInfoW,malloc,GetLocaleInfoW,WideCharToMultiByte,free,GetLocaleInfoA, 30_2_7C00F34C
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: _resetstkoflw,malloc,GetLocaleInfoW,WideCharToMultiByte,free, 30_2_7C00F3FF
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-03N37.tmp\SetupSteadyMouse1.3_ObsoleteFreeVersionRepackaged.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\notepad.exe Queries volume information: C:\Program Files (x86)\SteadyMouse\README.txt VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_100062E3 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter, 30_2_100062E3
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_7C02EAD4 _ftime,GetSystemTimeAsFileTime,__aulldiv,GetTimeZoneInformation,__aulldiv,__aullrem,__aulldiv, 30_2_7C02EAD4
Source: C:\Program Files (x86)\SteadyMouse\SteadyMouse.exe Code function: 30_2_100017B0 GetVersionExA,GetCommandLineA,TlsSetValue,GetCurrentThreadId, 30_2_100017B0
No contacted IP infos