Windows Analysis Report
Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe

Overview

General Information

Sample name: Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe
Analysis ID: 1438600
MD5: b543ca28c1fc8be534a8a701a0a96964
SHA1: df7680b5721f14631bd12aa7511171e5dd36e2e9
SHA256: bdb793b89f3ac3487cac8d5333d12ce2969c22de97941eab01a2c55b9f97b4f9
Infos:

Detection

Score: 3
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Checks for available system drives (often done to infect USB drives)
Creates a process in suspended mode (likely to inject code)
Drops PE files
File is packed with WinRar
Found dropped PE file which has not been started or loaded
Queries the volume information (name, serial number etc) of a device
Uses 32bit PE files

Classification

Source: Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Windows\System32\msiexec.exe File opened: z:
Source: C:\Windows\System32\msiexec.exe File opened: x:
Source: C:\Windows\System32\msiexec.exe File opened: v:
Source: C:\Windows\System32\msiexec.exe File opened: t:
Source: C:\Windows\System32\msiexec.exe File opened: r:
Source: C:\Windows\System32\msiexec.exe File opened: p:
Source: C:\Windows\System32\msiexec.exe File opened: n:
Source: C:\Windows\System32\msiexec.exe File opened: l:
Source: C:\Windows\System32\msiexec.exe File opened: j:
Source: C:\Windows\System32\msiexec.exe File opened: h:
Source: C:\Windows\System32\msiexec.exe File opened: f:
Source: C:\Windows\System32\msiexec.exe File opened: b:
Source: C:\Windows\System32\msiexec.exe File opened: y:
Source: C:\Windows\System32\msiexec.exe File opened: w:
Source: C:\Windows\System32\msiexec.exe File opened: u:
Source: C:\Windows\System32\msiexec.exe File opened: s:
Source: C:\Windows\System32\msiexec.exe File opened: q:
Source: C:\Windows\System32\msiexec.exe File opened: o:
Source: C:\Windows\System32\msiexec.exe File opened: m:
Source: C:\Windows\System32\msiexec.exe File opened: k:
Source: C:\Windows\System32\msiexec.exe File opened: i:
Source: C:\Windows\System32\msiexec.exe File opened: g:
Source: C:\Windows\System32\msiexec.exe File opened: e:
Source: C:\Windows\SysWOW64\msiexec.exe File opened: c:
Source: C:\Windows\System32\msiexec.exe File opened: a:
Source: Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engine Classification label: clean3.winEXE@8/8@0/0
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe File created: C:\Users\user\AppData\Local\Temp\RarSFX0
Source: Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe File read: C:\Windows\win.ini
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe File read: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe
Source: unknown Process created: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe "C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe"
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Process created: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe "C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe" /w
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Process created: C:\Windows\SysWOW64\msiexec.exe MSIEXEC.EXE /i "C:\Users\user\AppData\Local\Temp\RarSFX0\Lakes Environmental WRPLOT View - Freeware V.8.0.2.msi" SETUPEXEDIR="C:\Users\user\AppData\Local\Temp\RarSFX0" SETUPEXENAME="setup.exe"
Source: unknown Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F87BDED09FA11A60C7FEB9A0B8A11B7C C
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Process created: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe "C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe" /w
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Process created: C:\Windows\SysWOW64\msiexec.exe MSIEXEC.EXE /i "C:\Users\user\AppData\Local\Temp\RarSFX0\Lakes Environmental WRPLOT View - Freeware V.8.0.2.msi" SETUPEXEDIR="C:\Users\user\AppData\Local\Temp\RarSFX0" SETUPEXENAME="setup.exe"
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F87BDED09FA11A60C7FEB9A0B8A11B7C C
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: aclayers.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: mpr.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: sfc.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: sfc_os.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: riched32.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: riched20.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: usp10.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: msls31.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: propsys.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: profapi.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: edputil.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: urlmon.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: iertutil.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: srvcli.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: netutils.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: sspicli.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: appresolver.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: bcp47langs.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: slc.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: sppc.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: msi.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Section loaded: textshaping.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: srpapi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: tsappcmp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: textinputframework.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: coreuicomponents.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wldp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: propsys.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: textshaping.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: netapi32.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wkscli.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: netutils.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: version.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mscoree.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: profapi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sspicli.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msihnd.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: dwmapi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: pcacli.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: oleacc.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: windowscodecs.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe File written: C:\Users\user\AppData\Local\Temp\RarSFX0\0x0409.ini
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Window found: window name: RichEdit
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe File opened: C:\Windows\SysWOW64\riched32.dll
Source: Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Static file information: File size 21640831 > 1048576
Source: Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe File created: C:\Users\user\AppData\Local\Temp\RarSFX0\__tmp_rar_sfx_access_check_5079359
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe File created: C:\Users\user\AppData\Local\Temp\RarSFX0\instmsiw.exe Jump to dropped file
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe File created: C:\Users\user\AppData\Local\Temp\RarSFX0\instmsia.exe Jump to dropped file
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe File created: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe File created: C:\Users\user\AppData\Local\Temp\MSI9A55.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\RarSFX0\instmsiw.exe Jump to dropped file
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\RarSFX0\instmsia.exe Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI9A55.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe File Volume queried: C:\Users\user\AppData\Local\Temp FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe Process created: C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe "C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe" /w
Source: C:\Windows\SysWOW64\msiexec.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation
⊘No contacted IP infos