Windows Analysis Report
Recorder_System_v1.10.0048.exe

Overview

General Information

Sample name: Recorder_System_v1.10.0048.exe
Analysis ID: 1432274
MD5: a9042018e74f1fc91ebfc730a295c9b4
SHA1: f8c642249bad0286b7d61867c1bb633a6c991608
SHA256: 5ffe4b15c63ad89d31c155585fae5a7a95cdd77b2300329b5c5a1a400b087541
Infos:

Detection

Score: 36
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Antivirus detection for URL or domain
Allocates memory in foreign processes
Found direct / indirect Syscall (likely to bypass EDR)
Initial sample is a PE file and has a suspicious name
Loading BitLocker PowerShell Module
Queries sensitive service information (via WMI, MSSMBios_RawSMBiosTables, often done to detect sandboxes)
Writes to foreign memory regions
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates driver files
Creates files inside the system directory
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

AV Detection

barindex
Source: http://pesterbdd.com/images/Pester.png URL Reputation: Label: malware
Source: Recorder_System_v1.10.0048.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Kiloview End User License Agreement of Kiloview NDI RecorderThis Kiloview End User License Agreement of Kiloview NDI Recorder (here after called "EULA" or "the license agreement") is made available by Changsha KILOVIEW Electronics CO. LTD. (here after called "Kiloview"). If you are the direct user of Kiloview NDI Recorder please read this EULA carefully before you use them as it governs your use of the Software.You shall also be aware that the Software and all copyrights patents trademarks trade secrets and other intellectual property rights associated therewith are and shall remain the property of Kiloview. Furthermore the User acknowledges and agrees that the source and object code of the Software and the format directories queries algorithms structure and organization of the Software are the intellectual property and proprietary and confidential information of Kiloview and its affiliates licensors and suppliers. Nothing in this EULA shall give to the User or any other person any right to access or use the Source Code or constitute any license of the Source Code. Except as expressly stated in this License the User is not granted any intellectual property rights in or to the Software by implication estoppel or other legal theory and all rights in and to the Software not expressly granted in this License are hereby reserved and retained by Kiloview.In the course of building and using the Software you may provide Kiloview with such personal data like first name last name email address company name etc. The information will be used to contact or identify you and to smooth your registration by sending verification code and provide or offer software updates and instructions. We will not send you advertising information nor will we disclose your personal data.Personal Data is or may be used for the following purposes: (a) to provide and improve the Software Content Services and other features and content offered by Kiloview (b) to administer the use of the Software (c) to fulfill requests the User may make (d) to and (e) to provide the User with further information and offers from Kiloview that we believe you may find useful or interesting including newsletters marketing or promotional materials and other information on services and products offered by Kiloview.Definitions"Software" refers to a NDI Recorder designed and developed by Kiloview for all NDI sources.Grant of LicenseUpon your use and purchase of Kiloview NDI Recorder you are granted to use the software under the terms of this EULA.Restrictions on Use1. You shall use the Software strictly in accordance to the terms herein and during or after the term you shall not: a) modify sell transfer resell for profits distribute or create derivative work based on the Software or any part
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Kiloview End User License Agreement of Kiloview NDI RecorderThis Kiloview End User License Agreement of Kiloview NDI Recorder (here after called "EULA" or "the license agreement") is made available by Changsha KILOVIEW Electronics CO. LTD. (here after called "Kiloview"). If you are the direct user of Kiloview NDI Recorder please read this EULA carefully before you use them as it governs your use of the Software.You shall also be aware that the Software and all copyrights patents trademarks trade secrets and other intellectual property rights associated therewith are and shall remain the property of Kiloview. Furthermore the User acknowledges and agrees that the source and object code of the Software and the format directories queries algorithms structure and organization of the Software are the intellectual property and proprietary and confidential information of Kiloview and its affiliates licensors and suppliers. Nothing in this EULA shall give to the User or any other person any right to access or use the Source Code or constitute any license of the Source Code. Except as expressly stated in this License the User is not granted any intellectual property rights in or to the Software by implication estoppel or other legal theory and all rights in and to the Software not expressly granted in this License are hereby reserved and retained by Kiloview.In the course of building and using the Software you may provide Kiloview with such personal data like first name last name email address company name etc. The information will be used to contact or identify you and to smooth your registration by sending verification code and provide or offer software updates and instructions. We will not send you advertising information nor will we disclose your personal data.Personal Data is or may be used for the following purposes: (a) to provide and improve the Software Content Services and other features and content offered by Kiloview (b) to administer the use of the Software (c) to fulfill requests the User may make (d) to and (e) to provide the User with further information and offers from Kiloview that we believe you may find useful or interesting including newsletters marketing or promotional materials and other information on services and products offered by Kiloview.Definitions"Software" refers to a NDI Recorder designed and developed by Kiloview for all NDI sources.Grant of LicenseUpon your use and purchase of Kiloview NDI Recorder you are granted to use the software under the terms of this EULA.Restrictions on Use1. You shall use the Software strictly in accordance to the terms herein and during or after the term you shall not: a) modify sell transfer resell for profits distribute or create derivative work based on the Software or any part
Source: Recorder_System_v1.10.0048.exe Static PE information: certificate valid
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: Recorder_System_v1.10.0048.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_hangul.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_pinyin.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_openwnn.pdb<< source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_thai.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_tcime.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_pinyin.pdb11 source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_openwnn.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_tcime.pdb&& source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Base Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Base\ButtonStyle.qmlc Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick\Controls Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System Jump to behavior
Source: Joe Sandbox View JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: global traffic HTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A4109000CC6X-BM-CBT: 1696420817X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 60X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: 0912CF9094994CFA88DE52C6FB19D4E1X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A4109000CC6X-MSEdge-ExternalExp: bfbwsbrs0830tf,d-thshldspcl40,msbdsborgv2co,msbwdsbi920t1,spofglclicksh-c2,webtophit0r_t,wsbmsaqfuxtc,wsbqfasmsall_t,wsbqfminiserp400,wsbref-tX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=0; DaylightBias=-60; TimeZoneKeyName=GMT Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2237Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=6666694284484FA1B35CCB433D42E997; _SS=SID=193A581F83766B4319784BBF829B6A16&CPID=1696420820117&AC=1&CPH=e5c79613&CBV=39942242; _EDGE_S=SID=193A581F83766B4319784BBF829B6A16; SRCHUID=V=2&GUID=BA43D82178364AEA9C1EE6C32BE93416&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231003; SRCHHPGUSR=SRCHLANG=en&LUT=1696420817741&IPMH=425591ef&IPMID=1696420817913&HV=1696417346; ANON=A=6D8F9DF00282E660E425530EFFFFFFFF; CortanaAppUID=4C9C2B2D0465FD7A42C74C7E93CFB630; MUIDB=6666694284484FA1B35CCB433D42E997
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 23.56.6.162
Source: unknown TCP traffic detected without corresponding DNS query: 23.56.6.162
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 172.64.149.23
Source: unknown TCP traffic detected without corresponding DNS query: 172.64.149.23
Source: unknown TCP traffic detected without corresponding DNS query: 104.18.38.233
Source: unknown TCP traffic detected without corresponding DNS query: 104.18.38.233
Source: unknown TCP traffic detected without corresponding DNS query: 172.64.149.23
Source: unknown TCP traffic detected without corresponding DNS query: 172.64.149.23
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 23.55.103.43
Source: unknown TCP traffic detected without corresponding DNS query: 23.55.103.43
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=65Oa4kKcCE2B2pL&MD=WhAthezU HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=65Oa4kKcCE2B2pL&MD=WhAthezU HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknown HTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A4109000CC6X-BM-CBT: 1696420817X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 60X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: 0912CF9094994CFA88DE52C6FB19D4E1X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A4109000CC6X-MSEdge-ExternalExp: bfbwsbrs0830tf,d-thshldspcl40,msbdsborgv2co,msbwdsbi920t1,spofglclicksh-c2,webtophit0r_t,wsbmsaqfuxtc,wsbqfasmsall_t,wsbqfminiserp400,wsbref-tX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=0; DaylightBias=-60; TimeZoneKeyName=GMT Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2237Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=6666694284484FA1B35CCB433D42E997; _SS=SID=193A581F83766B4319784BBF829B6A16&CPID=1696420820117&AC=1&CPH=e5c79613&CBV=39942242; _EDGE_S=SID=193A581F83766B4319784BBF829B6A16; SRCHUID=V=2&GUID=BA43D82178364AEA9C1EE6C32BE93416&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231003; SRCHHPGUSR=SRCHLANG=en&LUT=1696420817741&IPMH=425591ef&IPMID=1696420817913&HV=1696417346; ANON=A=6D8F9DF00282E660E425530EFFFFFFFF; CortanaAppUID=4C9C2B2D0465FD7A42C74C7E93CFB630; MUIDB=6666694284484FA1B35CCB433D42E997
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1
Source: Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/2
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/=1
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/K
Source: Recorder System.exe, 00000008.00000003.3352744268.0000020128200000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/auth/get.json
Source: Recorder System.exe, 00000008.00000003.3236601604.00000201274F2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/ntp/diff.json
Source: Recorder System.exe, 00000008.00000003.3236601604.00000201274F2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/ntp/diff.json8
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/ntp/diff.jsonH
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/ntp/diff.jsonKq&
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/ntp/get.json
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/ntp/get.json1
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/ntp/get.json:65534/
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/ntp/get.jsonL
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/ntp/get.jsonl
Source: Recorder System.exe, 00000008.00000003.3236601604.00000201274F2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/output/get.json?project_id=1
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/output/get.json?project_id=1E
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/output/get.json?project_id=1KX
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/output/get.json?project_id=1~
Source: Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/performance/getSys.json
Source: Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/performance/getSys.json%
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/performance/getSys.json.1:65534/u
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/performance/getSys.jsonid=1
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/performance/getSys.jsonnP
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/project/getList.json
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/record/get.json?project_id=1
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/record/get.json?project_id=1_
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/record/get.json?project_id=1er
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/record/get.json?project_id=1s
Source: Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/source/get.json
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/storage/getAvailable.json
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/storage/getAvailable.jsonhtml?output=1
Source: Recorder System.exe, 00000008.00000003.3311842712.00000201285B2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/storage/getDeviceList.json
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/storage/getDeviceList.json0I
Source: Recorder System.exe, 00000008.00000003.3311842712.00000201285B2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/storage/getDeviceList.json8
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/api/storage/getDeviceList.jsonn
Source: Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1
Source: Recorder System.exe, 00000008.00000003.2910001985.0000020127483000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.2929949341.0000020127483000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1#/
Source: Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1#/home
Source: Recorder System.exe, 00000008.00000003.2930002756.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.2993437399.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1#/home&Array.isArray(e)?d(t
Source: Recorder System.exe, 00000008.00000003.2930002756.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.2993437399.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1#/home)
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1#/homeT
Source: Recorder System.exe, 00000008.00000003.2930002756.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.2993437399.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1#/homea
Source: Recorder System.exe, 00000008.00000003.2930002756.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1#/homeatch(t)
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1#/homedex.html?output=1
Source: Recorder System.exe, 00000008.00000003.2930002756.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.2993437399.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1#/homet)
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1&
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1534/
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1G
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1calX
Source: Recorder System.exe, 00000008.00000003.3306859801.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1id=1
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1json
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1l
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/index.html?output=1lX
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/lang/en.json
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/lang/en.json(
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/lang/en.jsontput=1
Source: Recorder System.exe, 00000008.00000003.3174345836.00000201273BA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/lang/en.jsontput=1=1
Source: Recorder System.exe, 00000008.00000003.3116261135.00000201271A2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:65534/static/favicon.png
Source: Recorder System.exe, 00000008.00000003.3225818355.0000020128239000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3377926199.0000020128200000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3256437375.0000020128239000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3279634870.0000020128200000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.3352744268.0000020128200000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://17.0.0.165534/index.html?output=1
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://code.google.com/p/chromium/issues/entry
Source: powershell.exe, 00000006.00000002.2953345209.000001A0F8D60000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: powershell.exe, 00000006.00000002.2958676236.000001A0F90D1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.m
Source: powershell.exe, 00000006.00000002.2959404528.000001A0F9102000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.mic
Source: powershell.exe, 00000006.00000002.2959404528.000001A0F9102000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.mic4
Source: powershell.exe, 00000006.00000002.2959404528.000001A0F9102000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.micP
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: powershell.exe, 00000006.00000002.2858291908.000001A0819B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000006.00000002.2936119512.000001A09006A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://nuget.org/NuGet.exe
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://ocsp.thawte.com0
Source: powershell.exe, 00000006.00000002.2858291908.000001A080227000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://pesterbdd.com/images/Pester.png
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://primer.com
Source: powershell.exe, 00000006.00000002.2858291908.000001A08092E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000006.00000002.2858291908.000001A080227000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: powershell.exe, 00000006.00000002.2858291908.000001A080001000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: powershell.exe, 00000006.00000002.2858291908.000001A08092E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000006.00000002.2858291908.000001A080227000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/wsdl/
Source: Recorder_System_v1.10.0048.exe, 00000000.00000003.1784888881.000000007FBE0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.exe, 00000000.00000003.1784363744.0000000002580000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000000.1786143348.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: http://skygz.taobao.com
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://t1.symcb.com/ThawtePCA.crl0
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://t2.symcb.com0
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://tl.symcb.com/tl.crl0
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://tl.symcb.com/tl.crt0
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://tl.symcd.com0&
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: powershell.exe, 00000006.00000002.2858291908.000001A080227000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
Source: Recorder_System_v1.10.0048.exe, 00000000.00000003.1784888881.000000007FBE0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.exe, 00000000.00000003.1784363744.0000000002580000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000000.1786143348.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: http://www.innosetup.com
Source: Recorder_System_v1.10.0048.exe, 00000000.00000000.1783171187.00000000004B7000.00000002.00000001.01000000.00000003.sdmp, Recorder_System_v1.10.0048.exe, 00000000.00000003.1784888881.000000007FBE0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.exe, 00000000.00000003.1784363744.0000000002580000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.exe, 00000000.00000003.2757737505.0000000002306000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000000.1786730697.0000000000668000.00000002.00000001.01000000.00000004.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000003.2723283541.0000000002426000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.kiloview.com/
Source: Recorder_System_v1.10.0048.exe, 00000000.00000003.1783507148.0000000002580000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000003.1787745486.0000000003530000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.kiloview.com/0http://www.kiloview.com/0http://www.kiloview.com/0http://www.kiloview.com/
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2723283541.0000000002426000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.kiloview.com/9jB
Source: Recorder_System_v1.10.0048.exe, 00000000.00000003.2757737505.0000000002306000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.kiloview.com/Ah0
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2723283541.0000000002426000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.kiloview.com/aiB
Source: Recorder_System_v1.10.0048.exe, 00000000.00000003.1784888881.000000007FBE0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.exe, 00000000.00000003.1784363744.0000000002580000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000000.1786143348.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: http://www.remobjects.com/ps
Source: Recorder_System_v1.10.0048.exe, 00000000.00000003.1784888881.000000007FBE0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.exe, 00000000.00000003.1784363744.0000000002580000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000000.1786143348.0000000000401000.00000020.00000001.01000000.00000004.sdmp String found in binary or memory: http://www.skygz.com
Source: powershell.exe, 00000006.00000002.2858291908.000001A080001000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aka.ms/pscore68
Source: powershell.exe, 00000006.00000002.2858291908.000001A080227000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000006.00000002.2956344021.000001A0F8EB0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000006.00000002.2858291908.000001A081312000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000006.00000002.2858291908.000001A08162A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aka.ms/winsvr-2022-pshelp
Source: powershell.exe, 00000006.00000002.2858291908.000001A08162A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aka.ms/winsvr-2022-pshelpX
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore/category/extensions
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=pt-BRAtalho
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=pt-PTAtalho
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=roComanda
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=ru
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=skSkratka
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=slBli
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=sr
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=svGenv
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=swUmeondoa
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=te
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=th
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=trK
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=uk
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=vi
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=zh-CN
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=zh-TW
Source: powershell.exe, 00000006.00000002.2936119512.000001A09006A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/
Source: powershell.exe, 00000006.00000002.2936119512.000001A09006A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/Icon
Source: powershell.exe, 00000006.00000002.2936119512.000001A09006A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/License
Source: powershell.exe, 00000006.00000002.2858291908.000001A080227000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/Pester/Pester
Source: Recorder System.exe, 00000008.00000003.2796730525.00000201276F1000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.2797215811.0000020127841000.00000004.00000020.00020000.00000000.sdmp, Recorder System.exe, 00000008.00000003.2799992939.00000201276FD000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/js-cookie/js-cookie
Source: powershell.exe, 00000006.00000002.2858291908.000001A08162A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://go.micro
Source: powershell.exe, 00000006.00000002.2858291908.000001A0819B4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000006.00000002.2936119512.000001A09006A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://nuget.org/nuget.exe
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://passwords.google.com
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://passwords.google.comConta
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://passwords.google.comContul
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://passwords.google.comGoogle
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://passwords.google.comGoogle-kontoSparade
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://passwords.google.comKonta
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://passwords.google.comT
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://primer.com.Uporaba
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=pt-BR
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=pt-PT
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=ro
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=ru
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=sk
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=sl
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=sr
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=sv
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=sw
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=te
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=th
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=tr
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=uk
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=vi
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=zh-CN
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/?p=ui_supervised_users&hl=zh-TW
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/chrome/answer/6098869
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://support.google.com/cloudprint/answer/2541843
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.com
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.com$1
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/cloudprint#jobs
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.comC
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.comPesquisa
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.comT
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.comVyh
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://www.google.comWyszukiwarka
Source: Recorder_System_v1.10.0048.exe, 00000000.00000000.1783068315.0000000000401000.00000020.00000001.01000000.00000003.sdmp String found in binary or memory: https://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: https://www.thawte.com/cps0/
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp String found in binary or memory: https://www.thawte.com/repository0W
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:49742 version: TLS 1.2

System Summary

barindex
Source: initial sample Static PE information: Filename: Recorder_System_v1.10.0048.exe
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File created: C:\Program Files (x86)\Recorder System\OpenHardwareMonitorLib.sys Jump to behavior
Source: C:\Windows\System32\svchost.exe File created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 12_2_00007FFD9BADB772 12_2_00007FFD9BADB772
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 12_2_00007FFD9BADA9C6 12_2_00007FFD9BADA9C6
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 12_2_00007FFD9BADA4C9 12_2_00007FFD9BADA4C9
Source: Recorder_System_v1.10.0048.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-MNRBK.tmp.1.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-3SREB.tmp.1.dr Static PE information: Number of sections : 17 > 10
Source: is-RTIAS.tmp.1.dr Static PE information: Number of sections : 12 > 10
Source: is-PN0JG.tmp.1.dr Static PE information: Number of sections : 12 > 10
Source: is-1NU94.tmp.1.dr Static PE information: Number of sections : 12 > 10
Source: is-5LL7O.tmp.1.dr Static PE information: Number of sections : 12 > 10
Source: Recorder_System_v1.10.0048.exe, 00000000.00000003.2757737505.00000000022E8000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamekernel32j% vs Recorder_System_v1.10.0048.exe
Source: Recorder_System_v1.10.0048.exe, 00000000.00000000.1783171187.00000000004B7000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFileName vs Recorder_System_v1.10.0048.exe
Source: Recorder_System_v1.10.0048.exe, 00000000.00000003.1784888881.000000007FBE0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFileName vs Recorder_System_v1.10.0048.exe
Source: Recorder_System_v1.10.0048.exe, 00000000.00000003.1784363744.0000000002580000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFileName vs Recorder_System_v1.10.0048.exe
Source: Recorder_System_v1.10.0048.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engine Classification label: sus36.evad.winEXE@15/2038@0/3
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Users\user\AppData\Local\Programs Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Mutant created: NULL
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Mutant created: \Sessions\1\BaseNamedObjects\NewTek_AirPlay_UdpPingMutex
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\Access_ISABUS.HTP.Method
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3896:120:WilError_03
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Mutant created: \Sessions\1\BaseNamedObjects\NewTek_AirPlay_UdpSendMutex
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\Access_PCI
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\CLR_PerfMon_WrapMutex
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe File created: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp Jump to behavior
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File read: C:\Program Files (x86)\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe File read: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe "C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe"
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Process created: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp "C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp" /SL5="$402A6,102473945,718848,C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe"
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" Set-Executionpolicy remotesigned -Force
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process created: C:\Program Files (x86)\Recorder System\Recorder System.exe "C:\Program Files (x86)\Recorder System\Recorder System.exe"
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process created: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe "C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe" --type=renderer --disable-gpu-memory-buffer-video-frames --enable-threaded-compositing --use-gl=angle --enable-features=AllowContentInitiatedDataUrlNavigations,TracingServiceInProcess --disable-features=BackgroundFetch,BlinkGenPropertyTrees,MojoVideoCapture,NetworkServiceNotSupported,OriginTrials,SmsReceiver,UsePdfCompositorServiceForPrint,UseSurfaceLayerForVideo,VizDisplayCompositor,WebAuthentication,WebAuthenticationCable,WebPayments,WebUSB --lang=en-CH --webengine-schemes=qrc:sLV --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11831953104643474927 --renderer-client-id=3 --mojo-platform-channel-handle=3536 /prefetch:1
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -file C:/Users/user/AppData/Local/official-recorder/temp/gpu.ps1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Windows\System32\wbem\WmiApSrv.exe C:\Windows\system32\wbem\WmiApSrv.exe
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Process created: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp "C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp" /SL5="$402A6,102473945,718848,C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" Set-Executionpolicy remotesigned -Force Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process created: C:\Program Files (x86)\Recorder System\Recorder System.exe "C:\Program Files (x86)\Recorder System\Recorder System.exe" Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process created: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe "C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe" --type=renderer --disable-gpu-memory-buffer-video-frames --enable-threaded-compositing --use-gl=angle --enable-features=AllowContentInitiatedDataUrlNavigations,TracingServiceInProcess --disable-features=BackgroundFetch,BlinkGenPropertyTrees,MojoVideoCapture,NetworkServiceNotSupported,OriginTrials,SmsReceiver,UsePdfCompositorServiceForPrint,UseSurfaceLayerForVideo,VizDisplayCompositor,WebAuthentication,WebAuthenticationCable,WebPayments,WebUSB --lang=en-CH --webengine-schemes=qrc:sLV --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11831953104643474927 --renderer-client-id=3 --mojo-platform-channel-handle=3536 /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -file C:/Users/user/AppData/Local/official-recorder/temp/gpu.ps1 Jump to behavior
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: msftedit.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: windows.globalization.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: globinputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: windows.ui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: windowmanagementapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: inputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kdscli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: processing.ndi.lib.x64.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5httpserver.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: libcrypto-1_1-x64.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5webengine.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5quick.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5multimedia.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5widgets.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5gui.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5qml.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5websockets.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: classlibrary3.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5sslserverd.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5websockets.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5webenginecore.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5quick.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5gui.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5webchannel.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5qml.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5gui.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5gui.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5qmlmodels.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5networkd.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5cored.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140d.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ucrtbased.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5cored.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msvcp140d.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140d.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ucrtbased.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msvcp140d.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140d.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ucrtbased.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ucrtbased.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5positioning.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: d3d9.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dxva2.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: hid.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140_1d.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: opengl32.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: glu32.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: appxdeploymentclient.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: libegl.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: libglesv2.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5svg.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: processing.ndi.lib.advanced.x64.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: avformat-59.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: avcodec-59.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: avutil-57.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: avcodec-59.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: avutil-57.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mfplat.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: avutil-57.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: swresample-4.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: rtworkq.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: libssl-1_1-x64.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: libssl-1_1-x64.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: netprofm.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: npmproxy.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: processing.ndi.plugins.ipcam.x64.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5qmlworkerscript.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5quicktemplates2.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: qt5quickcontrols2.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mscms.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: coloradapterclient.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mmdevapi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: devobj.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mf.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mfreadwrite.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mfcaptureengine.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: devenum.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ksuser.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: avrt.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: audioses.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: midimap.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: msdmo.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dsound.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: quartz.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: windows.devices.enumeration.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: structuredquery.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: windows.globalization.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: icu.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mswb7.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: devdispitemprovider.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: ddores.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: defaultdevicemanager.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: d3dcompiler_47.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: d3dcompiler_47.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: kbdus.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: comppkgsup.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: mfh264enc.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: windows.media.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: windows.applicationmodel.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Windows\System32\svchost.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exe Section loaded: qmgr.dll
Source: C:\Windows\System32\svchost.exe Section loaded: bitsperf.dll
Source: C:\Windows\System32\svchost.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exe Section loaded: xmllite.dll
Source: C:\Windows\System32\svchost.exe Section loaded: firewallapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: esent.dll
Source: C:\Windows\System32\svchost.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dnsapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: iphlpapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: fwbase.dll
Source: C:\Windows\System32\svchost.exe Section loaded: wldp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exe Section loaded: profapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: flightsettings.dll
Source: C:\Windows\System32\svchost.exe Section loaded: policymanager.dll
Source: C:\Windows\System32\svchost.exe Section loaded: msvcp110_win.dll
Source: C:\Windows\System32\svchost.exe Section loaded: netprofm.dll
Source: C:\Windows\System32\svchost.exe Section loaded: npmproxy.dll
Source: C:\Windows\System32\svchost.exe Section loaded: bitsigd.dll
Source: C:\Windows\System32\svchost.exe Section loaded: upnp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ssdpapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\svchost.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\svchost.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: netutils.dll
Source: C:\Windows\System32\svchost.exe Section loaded: appxdeploymentclient.dll
Source: C:\Windows\System32\svchost.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\svchost.exe Section loaded: wsmauto.dll
Source: C:\Windows\System32\svchost.exe Section loaded: miutils.dll
Source: C:\Windows\System32\svchost.exe Section loaded: wsmsvc.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dsrole.dll
Source: C:\Windows\System32\svchost.exe Section loaded: pcwum.dll
Source: C:\Windows\System32\svchost.exe Section loaded: mi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: userenv.dll
Source: C:\Windows\System32\svchost.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: wkscli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Windows\System32\svchost.exe Section loaded: msv1_0.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ntlmshared.dll
Source: C:\Windows\System32\svchost.exe Section loaded: cryptdll.dll
Source: C:\Windows\System32\svchost.exe Section loaded: webio.dll
Source: C:\Windows\System32\svchost.exe Section loaded: mswsock.dll
Source: C:\Windows\System32\svchost.exe Section loaded: winnsi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: fwpuclnt.dll
Source: C:\Windows\System32\svchost.exe Section loaded: rasadhlp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: rmclient.dll
Source: C:\Windows\System32\svchost.exe Section loaded: usermgrcli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: execmodelclient.dll
Source: C:\Windows\System32\svchost.exe Section loaded: propsys.dll
Source: C:\Windows\System32\svchost.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\svchost.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\svchost.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Windows\System32\svchost.exe Section loaded: execmodelproxy.dll
Source: C:\Windows\System32\svchost.exe Section loaded: resourcepolicyclient.dll
Source: C:\Windows\System32\svchost.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\svchost.exe Section loaded: samcli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: samlib.dll
Source: C:\Windows\System32\svchost.exe Section loaded: es.dll
Source: C:\Windows\System32\svchost.exe Section loaded: bitsproxy.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dhcpcsvc6.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dhcpcsvc.dll
Source: C:\Windows\System32\svchost.exe Section loaded: schannel.dll
Source: C:\Windows\System32\svchost.exe Section loaded: mskeyprotect.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ncrypt.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ncryptsslp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\svchost.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dpapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5core.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5webenginecore.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: msvcp140.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: vcruntime140.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: mpr.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: version.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: netapi32.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: msvcp140.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: vcruntime140.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5quick.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5gui.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5webchannel.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5qml.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5network.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5positioning.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: dbghelp.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: usp10.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: version.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: ncrypt.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: secur32.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: urlmon.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: dwrite.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: wtsapi32.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: d3d9.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: d3d11.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: dxva2.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: hid.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: msvcp140.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: vcruntime140.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: vcruntime140.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: vcruntime140_1.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5qmlmodels.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5qml.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5gui.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5network.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: d3d11.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5qml.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: qt5network.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: dnsapi.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: srvcli.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: ntasn1.dll
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Section loaded: profapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kdscli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: pdh.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wtsapi32.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msscntrs.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasctrs.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasman.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: tapiperf.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: usbperf.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wbemcomn.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: napinsp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: pnrpnsp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshbth.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: nlaapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iphlpapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mswsock.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dnsapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: winrnr.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: fwpuclnt.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasadhlp.dll
Source: C:\Windows\System32\wbem\WmiApSrv.exe Section loaded: wbemcomn.dll
Source: C:\Windows\System32\wbem\WmiApSrv.exe Section loaded: loadperf.dll
Source: C:\Windows\System32\wbem\WmiApSrv.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\wbem\WmiApSrv.exe Section loaded: amsi.dll
Source: C:\Windows\System32\wbem\WmiApSrv.exe Section loaded: userenv.dll
Source: C:\Windows\System32\wbem\WmiApSrv.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32 Jump to behavior
Source: Recorder System.lnk.1.dr LNK file: ..\..\..\..\..\Program Files (x86)\Recorder System\Recorder System.exe
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File written: C:\Program Files (x86)\Recorder System\data\lang.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Window found: window name: TSelectLanguageForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: OK
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Kiloview End User License Agreement of Kiloview NDI RecorderThis Kiloview End User License Agreement of Kiloview NDI Recorder (here after called "EULA" or "the license agreement") is made available by Changsha KILOVIEW Electronics CO. LTD. (here after called "Kiloview"). If you are the direct user of Kiloview NDI Recorder please read this EULA carefully before you use them as it governs your use of the Software.You shall also be aware that the Software and all copyrights patents trademarks trade secrets and other intellectual property rights associated therewith are and shall remain the property of Kiloview. Furthermore the User acknowledges and agrees that the source and object code of the Software and the format directories queries algorithms structure and organization of the Software are the intellectual property and proprietary and confidential information of Kiloview and its affiliates licensors and suppliers. Nothing in this EULA shall give to the User or any other person any right to access or use the Source Code or constitute any license of the Source Code. Except as expressly stated in this License the User is not granted any intellectual property rights in or to the Software by implication estoppel or other legal theory and all rights in and to the Software not expressly granted in this License are hereby reserved and retained by Kiloview.In the course of building and using the Software you may provide Kiloview with such personal data like first name last name email address company name etc. The information will be used to contact or identify you and to smooth your registration by sending verification code and provide or offer software updates and instructions. We will not send you advertising information nor will we disclose your personal data.Personal Data is or may be used for the following purposes: (a) to provide and improve the Software Content Services and other features and content offered by Kiloview (b) to administer the use of the Software (c) to fulfill requests the User may make (d) to and (e) to provide the User with further information and offers from Kiloview that we believe you may find useful or interesting including newsletters marketing or promotional materials and other information on services and products offered by Kiloview.Definitions"Software" refers to a NDI Recorder designed and developed by Kiloview for all NDI sources.Grant of LicenseUpon your use and purchase of Kiloview NDI Recorder you are granted to use the software under the terms of this EULA.Restrictions on Use1. You shall use the Software strictly in accordance to the terms herein and during or after the term you shall not: a) modify sell transfer resell for profits distribute or create derivative work based on the Software or any part
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Window detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Kiloview End User License Agreement of Kiloview NDI RecorderThis Kiloview End User License Agreement of Kiloview NDI Recorder (here after called "EULA" or "the license agreement") is made available by Changsha KILOVIEW Electronics CO. LTD. (here after called "Kiloview"). If you are the direct user of Kiloview NDI Recorder please read this EULA carefully before you use them as it governs your use of the Software.You shall also be aware that the Software and all copyrights patents trademarks trade secrets and other intellectual property rights associated therewith are and shall remain the property of Kiloview. Furthermore the User acknowledges and agrees that the source and object code of the Software and the format directories queries algorithms structure and organization of the Software are the intellectual property and proprietary and confidential information of Kiloview and its affiliates licensors and suppliers. Nothing in this EULA shall give to the User or any other person any right to access or use the Source Code or constitute any license of the Source Code. Except as expressly stated in this License the User is not granted any intellectual property rights in or to the Software by implication estoppel or other legal theory and all rights in and to the Software not expressly granted in this License are hereby reserved and retained by Kiloview.In the course of building and using the Software you may provide Kiloview with such personal data like first name last name email address company name etc. The information will be used to contact or identify you and to smooth your registration by sending verification code and provide or offer software updates and instructions. We will not send you advertising information nor will we disclose your personal data.Personal Data is or may be used for the following purposes: (a) to provide and improve the Software Content Services and other features and content offered by Kiloview (b) to administer the use of the Software (c) to fulfill requests the User may make (d) to and (e) to provide the User with further information and offers from Kiloview that we believe you may find useful or interesting including newsletters marketing or promotional materials and other information on services and products offered by Kiloview.Definitions"Software" refers to a NDI Recorder designed and developed by Kiloview for all NDI sources.Grant of LicenseUpon your use and purchase of Kiloview NDI Recorder you are granted to use the software under the terms of this EULA.Restrictions on Use1. You shall use the Software strictly in accordance to the terms herein and during or after the term you shall not: a) modify sell transfer resell for profits distribute or create derivative work based on the Software or any part
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll Jump to behavior
Source: Recorder_System_v1.10.0048.exe Static PE information: certificate valid
Source: Recorder_System_v1.10.0048.exe Static file information: File size 103244216 > 1048576
Source: Recorder_System_v1.10.0048.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_hangul.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_pinyin.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_openwnn.pdb<< source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_thai.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp, Recorder_System_v1.10.0048.tmp, 00000001.00000002.2747259737.000000000018C000.00000004.00000010.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_tcime.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_pinyin.pdb11 source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_openwnn.pdb source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtvirtualkeyboard\plugins\virtualkeyboard\qtvirtualkeyboard_tcime.pdb&& source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2712606285.00000000063B0000.00000004.00001000.00020000.00000000.sdmp
Source: is-J7HE7.tmp.1.dr Static PE information: 0xD13A41F1 [Wed Mar 26 23:08:33 2081 UTC]
Source: is-TU764.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0x444f6
Source: is-Q5FKQ.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0x2e387
Source: is-MNRBK.tmp.1.dr Static PE information: real checksum: 0x27437c should be: 0x27ab3b
Source: Recorder_System_v1.10.0048.tmp.0.dr Static PE information: real checksum: 0x27437c should be: 0x26cf9f
Source: is-J7HE7.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0x18b2
Source: is-804L0.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0x1a6ea
Source: is-83BH1.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0x3515c4
Source: is-SHFJV.tmp.1.dr Static PE information: real checksum: 0x0 should be: 0x5a6e9
Source: Recorder_System_v1.10.0048.exe Static PE information: section name: .didata
Source: Recorder_System_v1.10.0048.tmp.0.dr Static PE information: section name: .didata
Source: is-MNRBK.tmp.1.dr Static PE information: section name: .didata
Source: is-RTIAS.tmp.1.dr Static PE information: section name: .xdata
Source: is-1NU94.tmp.1.dr Static PE information: section name: .xdata
Source: is-EUM4R.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-UI7R7.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-E91NQ.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-JD84L.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-4OUCQ.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-TIBQQ.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-MBHPB.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-GE8FV.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-MH0HG.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-F27G2.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-3SREB.tmp.1.dr Static PE information: section name: /4
Source: is-3SREB.tmp.1.dr Static PE information: section name: /19
Source: is-3SREB.tmp.1.dr Static PE information: section name: /31
Source: is-3SREB.tmp.1.dr Static PE information: section name: /45
Source: is-3SREB.tmp.1.dr Static PE information: section name: /57
Source: is-3SREB.tmp.1.dr Static PE information: section name: /70
Source: is-3SREB.tmp.1.dr Static PE information: section name: /81
Source: is-3SREB.tmp.1.dr Static PE information: section name: /92
Source: is-S4J4O.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-N1301.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-G8AU8.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-5FVBS.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-MP9MT.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-0HJJO.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-AJ66B.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-MJI5C.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-DRGH1.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-EFF43.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-D9NLO.tmp.1.dr Static PE information: section name: _RDATA
Source: is-8H8RT.tmp.1.dr Static PE information: section name: _RDATA
Source: is-VGKVT.tmp.1.dr Static PE information: section name: _RDATA
Source: is-CQUNS.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-CUVSA.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-08QUI.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-K2N1T.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-R5K5O.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-THCCM.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-OH7NK.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-PQ3NI.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-K7O5H.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-N8GIK.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-EADOB.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-KMNA3.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-KV5D3.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-4IBFD.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-0QFR5.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-VKBN9.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-CKTA5.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-T1S7O.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-LT1NT.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-VCRLV.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-G1MA9.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-PN0JG.tmp.1.dr Static PE information: section name: .xdata
Source: is-5LL7O.tmp.1.dr Static PE information: section name: .xdata
Source: is-Q5FKQ.tmp.1.dr Static PE information: section name: .nep
Source: is-804L0.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-83BH1.tmp.1.dr Static PE information: section name: .00cfg
Source: is-T9U84.tmp.1.dr Static PE information: section name: .didat
Source: is-F4125.tmp.1.dr Static PE information: section name: .qtmetad
Source: is-SIQ9G.tmp.1.dr Static PE information: section name: _RDATA
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 12_2_00007FFD9BAD2B14 push eax; iretd 12_2_00007FFD9BAD2B41
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 12_2_00007FFD9BAD8615 push ebx; retf 0009h 12_2_00007FFD9BAD877A
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_local.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x86\is-BIPF8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-G8AU8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\msvcp140d.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-4U359.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\styles\is-E91NQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-6C5RI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-9335K.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Gui.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\ucrtbased.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\position\is-PQ3NI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\playlistformats\is-THCCM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\Record.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\platforms\is-R5K5O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-4IBFD.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\vcruntime140_app.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-KMNA3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-EALVR.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\avutil-57.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\scenegraph\is-UI7R7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-T1S7O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\swresample-4.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtWebEngine\is-MH0HG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Quick.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-5ICT0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\OpenHardwareMonitorLib.sys (copy)
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_preview.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\position\is-K7O5H.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-0L3BH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\bearer\qgenericbearer.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-3UTOM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQml\Models.2\is-PKGVS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\styles\qwindowsvistastyle.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Users\user\AppData\Local\Temp\is-N1VOU.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-MP9MT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\playlistformats\qtmultimedia_m3u.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\position\qtposition_winrt.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Layouts\is-JD84L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-SHFJV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-F3CEC.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt\labs\folderlistmodel\is-G1MA9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Svg.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-V6SB1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-6OI4S.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x86\NewTek NDI Record.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\bin\disk\libstdc++-6.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\bin\disk\is-3SREB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-GPGMO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Window.2\windowplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-83BH1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-PN0JG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-MNRBK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Processing.NDI.Lib.x64.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Cored.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQml\RemoteObjects\is-6KIDD.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-SIQ9G.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\bin\disk\libwinpthread-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-VKBN9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Flat\qtquickextrasflatplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\dialogplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-DFN06.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Multimedia.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-5FVBS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\bin\disk\is-TU764.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5RemoteObjects.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5WebChannel.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-61F2F.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\audio\is-V9O52.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-85FK3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick.2\is-GE8FV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5WebEngineCore.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\platforms\qwindows.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\avformat-59.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-8H8RT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Imagine\is-F27G2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Templates.2\qtquicktemplates2plugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5QuickTemplates2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5SslServer.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-3GE9B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\position\is-OH7NK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-0QFR5.tmp Jump to dropped file
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File created: C:\Program Files (x86)\Recorder System\OpenHardwareMonitorLib.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-U1B79.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5SerialPort.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\libcrypto-1_1-x64.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Universal\is-EFF43.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-6544C.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\vcruntime140_1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtWebEngine\qtwebengineplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\OpenHardwareMonitorLib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-EADOB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Extras\is-EUM4R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-LT1NT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-VGKVT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-T9U84.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\avcodec-59.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Widgets.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\bin\disk\a.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-D9NLO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_profiler.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt\labs\settings\is-F4125.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\ClassLibrary2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-TRR89.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Material\is-AJ66B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\iconengines\qsvgicon.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-KV5D3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\crashdump.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Material\qtquickcontrols2materialstyleplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_tcp.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-N1301.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Recorder System.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-5C7MQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\iconengines\is-H1PR9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Imagine\qtquickcontrols2imaginestyleplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5HttpServer.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-G3KAI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\is-CQUNS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Core.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-7UJLL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-N8GIK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\ClassLibrary3.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-LS77V.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-S4J4O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-GFNU0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\vc_redist.x64.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\scenegraph\qsgd3d12backend.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-A78JG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-0HJJO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5WebSockets.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-CCV2G.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5QmlWorkerScript.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Templates.2\is-TIBQQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-20MOV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_server.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-L3NQ9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-PD6L0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Network.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\libGLESV2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5SslServerd.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\is-CUVSA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-M5BI4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\libEGL.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-6EG55.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\msvcp140_app.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQml\RemoteObjects\qtqmlremoteobjects.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-Q5FKQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\vcruntime140d.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Networkd.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\Application.NDIRecording.x64.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_nativedebugger.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-MP0LO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\position\qtposition_serialnmea.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls\qtquickcontrolsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-BR8E8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\audio\is-AIP0V.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-G5QB1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-CBLA4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\Private\dialogsprivateplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Extras\qtquickextrasplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\PrivateWidgets\widgetsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-C0GG4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Flat\is-DRGH1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\bin\disk\is-AM3KL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Processing.NDI.Lib.Advanced.x64.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_quickprofiler.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\bin\disk\libgcc_s_sjlj-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Universal\qtquickcontrols2universalstyleplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\PrivateWidgets\is-4OUCQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-S03US.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Window.2\is-MBHPB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-1NU94.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-CKTA5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\Application.NDIRecording.x64(new).exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-SGAAU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\vcruntime140_1d.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-VBRD9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQml\is-3ODCM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-M5UK8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_native.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x86\NewTek NDI Discovery Service.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQml\StateMachine\qtqmlstatemachine.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-KVNQ1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe File created: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Fusion\is-K2N1T.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick.2\qtquick2plugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls\is-MJI5C.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\is-VCRLV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\D3Dcompiler_47.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-RTIAS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-804L0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\Private\is-08QUI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-5LL7O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt\labs\folderlistmodel\qmlfolderlistmodelplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Qml.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x86\is-B5JKA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\Application.NDIRecording.x64(old).exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQml\qmlplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_debugger.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5WebEngine.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-J7HE7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\audio\qtaudio_windows.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_inspector.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\opengl32sw.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Fusion\qtquickcontrols2fusionstyleplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\bearer\is-GKC2P.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\qtquickcontrols2plugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\position\qtposition_positionpoll.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-TR3D0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\avdevice-59.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-O26DP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5QmlModels.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5QuickControls2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\Utilities\x64\NewTek NDI Discovery Service.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\qtgraphicaleffectsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\recorder.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt\labs\settings\qmlsettingsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\swscale-6.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\private\is-VCKO4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-09O1F.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-S1GPN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQuick\Layouts\qquicklayoutsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-OIS8P.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\is-053KA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\audio\qtaudio_wasapi.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\is-DTL5L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_messages.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\res\bin\disk\is-UKQUM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQml\StateMachine\is-AVBQ8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Qt5Positioning.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\Processing.NDI.Lib.DirectShow.x64.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\Program Files (x86)\Recorder System\QtQml\Models.2\modelsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recorder System.lnk Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Users\user\Desktop\Recorder_System_v1.10.0048.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\wbem\WmiApSrv.exe Process information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe WMI Queries: IWbemServices::ExecQuery - root\WMI : SELECT * FROM MSSMBios_RawSMBiosTables
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe WMI Queries: IWbemServices::ExecQuery - root\WMI : SELECT * FROM MSSMBios_RawSMBiosTables
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe WMI Queries: IWbemServices::ExecQuery - root\WMI : SELECT * FROM MSSMBios_RawSMBiosTables
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe WMI Queries: IWbemServices::ExecQuery - root\WMI : SELECT * FROM MSSMBios_RawSMBiosTables
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory allocated: 20108AD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory allocated: 20122E20000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 6789 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 1450 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Window / User API: threadDelayed 5697 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 6778
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 2236
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_local.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_tcp.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-N1301.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x86\is-BIPF8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-G8AU8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-4U359.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\styles\is-E91NQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-6C5RI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-5C7MQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\iconengines\is-H1PR9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-9335K.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Imagine\qtquickcontrols2imaginestyleplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\position\is-PQ3NI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\playlistformats\is-THCCM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-G3KAI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\Record.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\is-CQUNS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-7UJLL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\platforms\is-R5K5O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\vcruntime140_app.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-4IBFD.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-KMNA3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-N8GIK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-LS77V.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-EALVR.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-S4J4O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\scenegraph\qsgd3d12backend.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-GFNU0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\vc_redist.x64.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-0HJJO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\scenegraph\is-UI7R7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-CCV2G.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-T1S7O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Templates.2\is-TIBQQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-20MOV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_server.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtWebEngine\is-MH0HG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-PD6L0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-L3NQ9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_preview.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\OpenHardwareMonitorLib.sys (copy)
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-5ICT0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\is-CUVSA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-M5BI4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-6EG55.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\position\is-K7O5H.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-0L3BH.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\msvcp140_app.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQml\RemoteObjects\qtqmlremoteobjects.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-Q5FKQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\Application.NDIRecording.x64.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\bearer\qgenericbearer.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_nativedebugger.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\position\qtposition_serialnmea.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-MP0LO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls\qtquickcontrolsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\audio\is-AIP0V.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-BR8E8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-G5QB1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\Private\dialogsprivateplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-CBLA4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Extras\qtquickextrasplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-3UTOM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\PrivateWidgets\widgetsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQml\Models.2\is-PKGVS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\bin\disk\is-AM3KL.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Flat\is-DRGH1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\styles\qwindowsvistastyle.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-N1VOU.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-MP9MT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_quickprofiler.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\playlistformats\qtmultimedia_m3u.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\position\qtposition_winrt.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\bin\disk\libgcc_s_sjlj-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Universal\qtquickcontrols2universalstyleplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\PrivateWidgets\is-4OUCQ.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-SHFJV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Layouts\is-JD84L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-F3CEC.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-S03US.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\Qt\labs\folderlistmodel\is-G1MA9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Window.2\is-MBHPB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-1NU94.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-CKTA5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-V6SB1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\Application.NDIRecording.x64(new).exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-6OI4S.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x86\NewTek NDI Record.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-SGAAU.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\bin\disk\libstdc++-6.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-GPGMO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\bin\disk\is-3SREB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Window.2\windowplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQml\is-3ODCM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-83BH1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-M5UK8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-PN0JG.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_native.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-MNRBK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x86\NewTek NDI Discovery Service.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQml\StateMachine\qtqmlstatemachine.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQml\RemoteObjects\is-6KIDD.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-KVNQ1.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\bin\disk\libwinpthread-1.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-SIQ9G.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Flat\qtquickextrasflatplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-VKBN9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Fusion\is-K2N1T.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick.2\qtquick2plugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\dialogplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-DFN06.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\virtualkeyboard\is-5FVBS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls\is-MJI5C.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\Qt5RemoteObjects.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\bin\disk\is-TU764.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-VCRLV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-61F2F.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\audio\is-V9O52.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-RTIAS.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-804L0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\Private\is-08QUI.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-5LL7O.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\Qt\labs\folderlistmodel\qmlfolderlistmodelplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-85FK3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick.2\is-GE8FV.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\platforms\qwindows.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x86\is-B5JKA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\Application.NDIRecording.x64(old).exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQml\qmlplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-8H8RT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Imagine\is-F27G2.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_debugger.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Templates.2\qtquicktemplates2plugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-J7HE7.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\Qt5SslServer.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\audio\qtaudio_windows.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_inspector.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-3GE9B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\position\is-OH7NK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\opengl32sw.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-0QFR5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Fusion\qtquickcontrols2fusionstyleplugin.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\OpenHardwareMonitorLib.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\bearer\is-GKC2P.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\qtquickcontrols2plugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\position\qtposition_positionpoll.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-TR3D0.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\avdevice-59.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\Qt5SerialPort.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-U1B79.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-O26DP.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\NewTek NDI Discovery Service.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\qtgraphicaleffectsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-6544C.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Universal\is-EFF43.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtWebEngine\qtwebengineplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\recorder.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\OpenHardwareMonitorLib.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-EADOB.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\Qt\labs\settings\qmlsettingsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Extras\is-EUM4R.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\swscale-6.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\private\is-VCKO4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-LT1NT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-VGKVT.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-09O1F.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-T9U84.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\bin\disk\a.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-S1GPN.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Layouts\qquicklayoutsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-OIS8P.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\Utilities\x64\is-D9NLO.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\audio\qtaudio_wasapi.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\qmldbg_profiler.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\is-053KA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\Qt\labs\settings\is-F4125.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-DTL5L.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\ClassLibrary2.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\is-TRR89.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\res\bin\disk\is-UKQUM.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\iconengines\qsvgicon.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQml\StateMachine\is-AVBQ8.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Material\is-AJ66B.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\qmltooling\is-KV5D3.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\crashdump.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\Material\qtquickcontrols2materialstyleplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\QtQml\Models.2\modelsplugin.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Dropped PE file which has not been started: C:\Program Files (x86)\Recorder System\Processing.NDI.Lib.DirectShow.x64.dll (copy) Jump to dropped file
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 3916 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\System32\svchost.exe TID: 3672 Thread sleep time: -30000s >= -30000s
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4944 Thread sleep count: 6778 > 30
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4944 Thread sleep count: 2236 > 30
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1720 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 3732 Thread sleep time: -1844674407370954s >= -30000s
Source: C:\Windows\System32\svchost.exe File opened: PhysicalDrive0
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\d0010809 Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File Volume queried: C:\Users\user\AppData\Local\Kiloview\Recorder System\QtWebEngine\Default\blob_storage\84b40db6-5102-449d-9a83-6065507ecf8b FullSizeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File Volume queried: C:\Users\user\AppData\Local\Kiloview\Recorder System\cache\QtWebEngine\Default\Cache FullSizeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Base Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Base\ButtonStyle.qmlc Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick\Controls Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe File opened: C:\Program Files (x86)\Recorder System Jump to behavior
Source: Recorder System.exe, 00000008.00000003.3397153646.0000020128239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0
Source: Recorder System.exe, 00000008.00000003.3397153646.0000020128239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware, Inc.
Source: Recorder System.exe, 00000008.00000003.3397153646.0000020128239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware20,1
Source: Recorder System.exe, 00000008.00000003.3397153646.0000020128239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware Virtual RAM00000001VMW-4096MBRAM slot #0RAM slot #0
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2716711201.0000000000916000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\G
Source: Recorder System.exe, 00000008.00000003.3397153646.0000020128239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware, Inc.NoneVMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0VMware20,1
Source: Recorder System.exe, 00000008.00000003.3397153646.0000020128239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware SVGA IIES1371
Source: Recorder System.exe, 00000008.00000003.3397153646.0000020128239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware Virtual RAM
Source: Recorder System.exe, 00000008.00000003.3397153646.0000020128239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware, Inc.VMW201.00V.20829224.B64.221121184211/21/2022
Source: Recorder System.exe, 00000008.00000003.3397153646.0000020128239000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware SVGA II
Source: Recorder_System_v1.10.0048.tmp, 00000001.00000003.2745011340.00000000008AD000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}ms
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory allocated: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491A90000 protect: page read and write Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory allocated: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AA0000 protect: page no access Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory allocated: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD000 protect: page execute and read and write Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory allocated: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AB0000 protect: page read and write Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe NtCreateFile: Indirect: 0x7FFDEBF815E5 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491A90000 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD420 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220DA90 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD460 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D650 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD4A0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D790 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD4E0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220F8A0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD520 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D4D0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD560 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220F5A0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD5A0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D4B0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD5E0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220F4E0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD620 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D190 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD660 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D470 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD6A0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D5F0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD6E0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D5D0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD720 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D4F0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD760 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FFE2220D530 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AAD400 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FF641056540 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FF641056690 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FF641056760 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 1B491AB0000 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FF641056530 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FF641056750 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FF641056828 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FF641056830 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FF641055000 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Memory written: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe base: 7FF6410568B0 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process created: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe "C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe" --type=renderer --disable-gpu-memory-buffer-video-frames --enable-threaded-compositing --use-gl=angle --enable-features=AllowContentInitiatedDataUrlNavigations,TracingServiceInProcess --disable-features=BackgroundFetch,BlinkGenPropertyTrees,MojoVideoCapture,NetworkServiceNotSupported,OriginTrials,SmsReceiver,UsePdfCompositorServiceForPrint,UseSurfaceLayerForVideo,VizDisplayCompositor,WebAuthentication,WebAuthenticationCable,WebPayments,WebUSB --lang=en-CH --webengine-schemes=qrc:sLV --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11831953104643474927 --renderer-client-id=3 --mojo-platform-channel-handle=3536 /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -file C:/Users/user/AppData/Local/official-recorder/temp/gpu.ps1 Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process created: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe "c:\program files (x86)\recorder system\qtwebengineprocess.exe" --type=renderer --disable-gpu-memory-buffer-video-frames --enable-threaded-compositing --use-gl=angle --enable-features=allowcontentinitiateddataurlnavigations,tracingserviceinprocess --disable-features=backgroundfetch,blinkgenpropertytrees,mojovideocapture,networkservicenotsupported,origintrials,smsreceiver,usepdfcompositorserviceforprint,usesurfacelayerforvideo,vizdisplaycompositor,webauthentication,webauthenticationcable,webpayments,webusb --lang=en-ch --webengine-schemes=qrc:slv --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11831953104643474927 --renderer-client-id=3 --mojo-platform-channel-handle=3536 /prefetch:1
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Process created: C:\Program Files (x86)\Recorder System\QtWebEngineProcess.exe "c:\program files (x86)\recorder system\qtwebengineprocess.exe" --type=renderer --disable-gpu-memory-buffer-video-frames --enable-threaded-compositing --use-gl=angle --enable-features=allowcontentinitiateddataurlnavigations,tracingserviceinprocess --disable-features=backgroundfetch,blinkgenpropertytrees,mojovideocapture,networkservicenotsupported,origintrials,smsreceiver,usepdfcompositorserviceforprint,usesurfacelayerforvideo,vizdisplaycompositor,webauthentication,webauthenticationcable,webpayments,webusb --lang=en-ch --webengine-schemes=qrc:slv --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11831953104643474927 --renderer-client-id=3 --mojo-platform-channel-handle=3536 /prefetch:1 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-UNUI8.tmp\Recorder_System_v1.10.0048.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.LocalAccounts\1.0.0.0\Microsoft.PowerShell.LocalAccounts.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\platforms\qwindows.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\styles\qwindowsvistastyle.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\crashdump.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\iconengines\qsvgicon.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\imageformats\qgif.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\imageformats\qico.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\imageformats\qjpeg.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\imageformats\qtga.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\imageformats\qtiff.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\imageformats\qwbmp.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\recorder.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Users\user\AppData\Local\official-recorder\lang.ini VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Users\user\AppData\Local\official-recorder\lang.ini VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\bearer\qgenericbearer.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\translations\qt_en.qm VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick.2\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick.2\qtquick2plugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Window.2\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Window.2\windowplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\dialogplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Controls\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Controls\qtquickcontrolsplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\qtgraphicaleffectsplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtWebEngine\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtWebEngine\qtwebengineplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Controls.2\qtquickcontrols2plugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Templates.2\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Templates.2\qtquicktemplates2plugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQml\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQml\qmlplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Private\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\Private\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\Private\dialogsprivateplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Layouts\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Layouts\qquicklayoutsplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\Qt\labs\folderlistmodel\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\Qt\labs\folderlistmodel\qmlfolderlistmodelplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\Qt\labs\settings\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\Qt\labs\settings\qmlsettingsplugin.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\qml\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Desktop\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\ClassLibrary3.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\qml\icons.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Dialogs\qml\icons.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\ClassLibrary2.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\OpenHardwareMonitorLib.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Base\images\arrow-down.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtQuick\Controls\Styles\Base\images\arrow-down.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\icon_sq_d.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\icon_sq_d.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\min.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\min.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\normal.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\normal.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\close.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\close.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\logo.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\logo.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\qml\en_us.qm VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\audio\qtaudio_wasapi.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\private\qmldir VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\tempsnip.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\img\tempsnip.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\index.html VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\static\css\app.css VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\static\js\manifest.7212102.js VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\static\js\vendor.7212102.js VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\static\js\app.7212102.js VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Users\user\AppData\Local\Kiloview\Recorder System\QtWebEngine\Default\Local Storage\leveldb\MANIFEST-000001 VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\lang\zh.json VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\static\js\3.7212102.js VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\static\js\0.7212102.js VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\lang\en.json VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\static\favicon.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\static\img\icon_auth_countdown.c83bc09.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Program Files (x86)\Recorder System\res\static\favicon.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Queries volume information: C:\Users\user\AppData\Local\official-recorder\log_20240426_190955.316.log VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Program Files (x86)\Recorder System\Recorder System.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs