Source: is-GR8PB.tmp.2.dr, is-LCDEV.tmp.2.dr | String found in binary or memory: http://icu-project.org |
Source: tKBxw8eOIV.tmp, 00000002.00000002.4020195154.0000000005C8A000.00000004.00001000.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000003.2181736491.0000000002648000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000000.2181054207.000000000065C000.00000002.00000001.01000000.00000009.sdmp, smartfiledefrag13.exe.2.dr, SmartFileDefrag.exe.3.dr, is-8F7LH.tmp.2.dr | String found in binary or memory: http://www.countnow.ru |
Source: tKBxw8eOIV.tmp, tKBxw8eOIV.tmp, 00000002.00000002.4018943988.0000000000401000.00000020.00000001.01000000.00000004.sdmp, tKBxw8eOIV.tmp.0.dr, is-5482O.tmp.2.dr | String found in binary or memory: http://www.innosetup.com/ |
Source: tKBxw8eOIV.exe | String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline |
Source: tKBxw8eOIV.exe | String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: tKBxw8eOIV.exe, 00000000.00000003.2161032856.0000000002128000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000003.2160780335.0000000002350000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, tKBxw8eOIV.tmp, 00000002.00000002.4018943988.0000000000401000.00000020.00000001.01000000.00000004.sdmp, tKBxw8eOIV.tmp.0.dr, is-5482O.tmp.2.dr | String found in binary or memory: http://www.remobjects.com/ps |
Source: tKBxw8eOIV.exe, 00000000.00000003.2161032856.0000000002128000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000003.2160780335.0000000002350000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000002.00000002.4018943988.0000000000401000.00000020.00000001.01000000.00000004.sdmp, tKBxw8eOIV.tmp.0.dr, is-5482O.tmp.2.dr | String found in binary or memory: http://www.remobjects.com/psU |
Source: smartfiledefrag13.exe, 00000003.00000002.4019290046.00000000008F2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://176.113.115.96/ |
Source: smartfiledefrag13.exe, 00000003.00000002.4019290046.00000000008F2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://176.113.115.96/Z |
Source: smartfiledefrag13.exe, 00000003.00000002.4019290046.0000000000905000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae14615677411efa3231678fbb38f926d19fe6595cd66946851e91fcd85241 |
Source: tKBxw8eOIV.exe, 00000000.00000003.2160476522.0000000002121000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000002.4019373102.0000000002121000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000003.2160402309.0000000002350000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000002.00000003.2162931488.0000000002128000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000002.00000002.4019719142.0000000002128000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000002.00000003.2162852704.00000000030F0000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000002.00000002.4019287541.00000000006C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.easycutstudio.com/support.html |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_0040840C | 0_2_0040840C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00470C74 | 2_2_00470C74 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0043533C | 2_2_0043533C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004813C4 | 2_2_004813C4 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00467848 | 2_2_00467848 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004303D0 | 2_2_004303D0 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0044453C | 2_2_0044453C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004885E0 | 2_2_004885E0 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00434638 | 2_2_00434638 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00444AE4 | 2_2_00444AE4 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0048ED0C | 2_2_0048ED0C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00430F5C | 2_2_00430F5C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0045F16C | 2_2_0045F16C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004451DC | 2_2_004451DC |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0045B21C | 2_2_0045B21C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004455E8 | 2_2_004455E8 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00487680 | 2_2_00487680 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0046989C | 2_2_0046989C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00451A30 | 2_2_00451A30 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0043DDC4 | 2_2_0043DDC4 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_00401000 | 3_2_00401000 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_004067B7 | 3_2_004067B7 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_609660FA | 3_2_609660FA |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6092114F | 3_2_6092114F |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6091F2C9 | 3_2_6091F2C9 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096923E | 3_2_6096923E |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6093323D | 3_2_6093323D |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095C314 | 3_2_6095C314 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60950312 | 3_2_60950312 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094D33B | 3_2_6094D33B |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6093B368 | 3_2_6093B368 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096748C | 3_2_6096748C |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6093F42E | 3_2_6093F42E |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60954470 | 3_2_60954470 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_609615FA | 3_2_609615FA |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096A5EE | 3_2_6096A5EE |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096D6A4 | 3_2_6096D6A4 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_609606A8 | 3_2_609606A8 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60932654 | 3_2_60932654 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60955665 | 3_2_60955665 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094B7DB | 3_2_6094B7DB |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6092F74D | 3_2_6092F74D |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60964807 | 3_2_60964807 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094E9BC | 3_2_6094E9BC |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60937929 | 3_2_60937929 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6093FAD6 | 3_2_6093FAD6 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096DAE8 | 3_2_6096DAE8 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094DA3A | 3_2_6094DA3A |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60936B27 | 3_2_60936B27 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60954CF6 | 3_2_60954CF6 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60950C6B | 3_2_60950C6B |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60966DF1 | 3_2_60966DF1 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60963D35 | 3_2_60963D35 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60909E9C | 3_2_60909E9C |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60951E86 | 3_2_60951E86 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60912E0B | 3_2_60912E0B |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60954FF8 | 3_2_60954FF8 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023C2A80 | 3_2_023C2A80 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023BBAFD | 3_2_023BBAFD |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023BD32F | 3_2_023BD32F |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023AE089 | 3_2_023AE089 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023B70C0 | 3_2_023B70C0 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023BB609 | 3_2_023BB609 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023C267D | 3_2_023C267D |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023BBF15 | 3_2_023BBF15 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023B874A | 3_2_023B874A |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_023C0DB4 | 3_2_023C0DB4 |
Source: smartfiledefrag13.exe, smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence'; |
Source: smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q); |
Source: smartfiledefrag13.exe, smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0 |
Source: smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: CREATE TABLE "%w"."%w_node"(nodeno INTEGER PRIMARY KEY, data BLOB);CREATE TABLE "%w"."%w_rowid"(rowid INTEGER PRIMARY KEY, nodeno INTEGER);CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY, parentnode INTEGER);INSERT INTO '%q'.'%q_node' VALUES(1, zeroblob(%d)) |
Source: smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB); |
Source: smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB); |
Source: smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx)); |
Source: smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s; |
Source: smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s; |
Source: smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB); |
Source: smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger'); |
Source: smartfiledefrag13.exe, smartfiledefrag13.exe, 00000003.00000003.2182652428.000000000082A000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.4021764200.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-9UG3I.tmp.2.dr | Binary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence' |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: msimg32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: sqlite3.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_004065C8 push 00406605h; ret | 0_2_004065FD |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_004040B5 push eax; ret | 0_2_004040F1 |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_00408104 push ecx; mov dword ptr [esp], eax | 0_2_00408109 |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_00404185 push 00404391h; ret | 0_2_00404389 |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_00404206 push 00404391h; ret | 0_2_00404389 |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_0040C218 push eax; ret | 0_2_0040C219 |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_004042E8 push 00404391h; ret | 0_2_00404389 |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_00404283 push 00404391h; ret | 0_2_00404389 |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | Code function: 0_2_00408F38 push 00408F6Bh; ret | 0_2_00408F63 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004849F4 push 00484B02h; ret | 2_2_00484AFA |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0040995C push 00409999h; ret | 2_2_00409991 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00458060 push 00458098h; ret | 2_2_00458090 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004860E4 push ecx; mov dword ptr [esp], ecx | 2_2_004860E9 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004062C4 push ecx; mov dword ptr [esp], eax | 2_2_004062C5 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004783C8 push ecx; mov dword ptr [esp], edx | 2_2_004783C9 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004104F0 push ecx; mov dword ptr [esp], edx | 2_2_004104F5 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00412938 push 0041299Bh; ret | 2_2_00412993 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0049AD44 pushad ; retf | 2_2_0049AD53 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0040CE48 push ecx; mov dword ptr [esp], edx | 2_2_0040CE4A |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00459378 push 004593BCh; ret | 2_2_004593B4 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0040F3A8 push ecx; mov dword ptr [esp], edx | 2_2_0040F3AA |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0040546D push eax; ret | 2_2_004054A9 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004434B4 push ecx; mov dword ptr [esp], ecx | 2_2_004434B8 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0040553D push 00405749h; ret | 2_2_00405741 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004055BE push 00405749h; ret | 2_2_00405741 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0040563B push 00405749h; ret | 2_2_00405741 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004056A0 push 00405749h; ret | 2_2_00405741 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0045186C push 0045189Fh; ret | 2_2_00451897 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00451A30 push ecx; mov dword ptr [esp], eax | 2_2_00451A35 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00495BE4 push ecx; mov dword ptr [esp], ecx | 2_2_00495BE9 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00419C38 push ecx; mov dword ptr [esp], ecx | 2_2_00419C3D |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-LCDEV.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-EORFE.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Temp\is-9OECC.tmp\_isetup\_shfoldr.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-GR8PB.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libEGL.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcr100.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-9UKKM.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Temp\is-9OECC.tmp\_isetup\_setup64.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5PrintSupport.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | File created: C:\ProgramData\SmartFileDefrag\SmartFileDefrag.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\unins000.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libGLESv2.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Temp\is-9OECC.tmp\_isetup\_iscrypt.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5Concurrent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\is-5482O.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\sqlite3.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-9UG3I.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-RNJ96.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-AQM23.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcp100.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-2QVUK.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuin51.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-5P6NV.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | File created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuuc51.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | File created: C:\ProgramData\SmartFileDefrag\sqlite3.dll | Jump to dropped file |
Source: C:\Users\user\Desktop\tKBxw8eOIV.exe | File created: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00423C1C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, | 2_2_00423C1C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00423C1C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus, | 2_2_00423C1C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004241EC IsIconic,SetActiveWindow,SetFocus, | 2_2_004241EC |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004241A4 IsIconic,SetActiveWindow, | 2_2_004241A4 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00418394 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient, | 2_2_00418394 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004843A8 IsIconic,GetWindowLongA,ShowWindow,ShowWindow, | 2_2_004843A8 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0042286C SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow, | 2_2_0042286C |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_0042F2F0 IsIconic,GetWindowLongA,GetWindowLongA,GetActiveWindow,MessageBoxA,SetActiveWindow,GetActiveWindow,MessageBoxA,SetActiveWindow, | 2_2_0042F2F0 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_004175A8 IsIconic,GetCapture, | 2_2_004175A8 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00417CDE IsIconic,SetWindowPos, | 2_2_00417CDE |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Code function: 2_2_00417CE0 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement, | 2_2_00417CE0 |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-LCDEV.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-9UG3I.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-EORFE.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-RNJ96.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-AQM23.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-9OECC.tmp\_isetup\_shfoldr.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcr100.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-GR8PB.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libEGL.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcp100.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-9UKKM.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-9OECC.tmp\_isetup\_setup64.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5PrintSupport.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-2QVUK.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\unins000.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libGLESv2.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-9OECC.tmp\_isetup\_iscrypt.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5Concurrent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuin51.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-5P6NV.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuuc51.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-8QKK3.tmp\tKBxw8eOIV.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\is-5482O.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_609660FA sqlite3_finalize,sqlite3_free,sqlite3_value_numeric_type,sqlite3_value_numeric_type,sqlite3_value_text,sqlite3_value_int,memcmp,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_strnicmp,sqlite3_mprintf,sqlite3_mprintf,sqlite3_malloc,sqlite3_free,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_bind_value, | 3_2_609660FA |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6090C1D6 sqlite3_clear_bindings,sqlite3_mutex_enter,sqlite3_mutex_leave, | 3_2_6090C1D6 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60963143 sqlite3_stricmp,sqlite3_bind_int64,sqlite3_mutex_leave, | 3_2_60963143 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096A2BD sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset, | 3_2_6096A2BD |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096923E sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_malloc,sqlite3_malloc,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_realloc,sqlite3_realloc,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_free, | 3_2_6096923E |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096A38C sqlite3_bind_int,sqlite3_column_int,sqlite3_step,sqlite3_reset, | 3_2_6096A38C |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096748C sqlite3_malloc,sqlite3_bind_int,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_reset,sqlite3_bind_int,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_malloc,sqlite3_bind_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_reset,memcmp,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_bind_int64,sqlite3_realloc,sqlite3_column_int,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_bind_int,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free, | 3_2_6096748C |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_609254B1 sqlite3_bind_zeroblob,sqlite3_mutex_leave, | 3_2_609254B1 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094B407 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, | 3_2_6094B407 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6090F435 sqlite3_bind_parameter_index, | 3_2_6090F435 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_609255D4 sqlite3_mutex_leave,sqlite3_bind_text16, | 3_2_609255D4 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_609255FF sqlite3_bind_text, | 3_2_609255FF |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096A5EE sqlite3_value_text,sqlite3_value_bytes,sqlite3_strnicmp,sqlite3_strnicmp,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_malloc,LdrInitializeThunk,sqlite3_column_int,sqlite3_column_int64,sqlite3_column_text,sqlite3_column_bytes,sqlite3_finalize,sqlite3_step,sqlite3_free,sqlite3_finalize,sqlite3_strnicmp,sqlite3_bind_int,sqlite3_column_int,sqlite3_step,sqlite3_reset,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_column_int64,sqlite3_column_int,sqlite3_column_text,sqlite3_column_bytes,sqlite3_step,sqlite3_finalize,sqlite3_strnicmp,sqlite3_strnicmp,sqlite3_bind_int,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_value_int,sqlite3_malloc,sqlite3_bind_null,sqlite3_step,sqlite3_reset,sqlite3_value_int,sqlite3_value_text,sqlite3_value_bytes,sqlite3_free, | 3_2_6096A5EE |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094B54C sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,memmove, | 3_2_6094B54C |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60925686 sqlite3_bind_int64,sqlite3_mutex_leave, | 3_2_60925686 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094A6C5 sqlite3_bind_int64,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_malloc,sqlite3_reset,sqlite3_free, | 3_2_6094A6C5 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_609256E5 sqlite3_bind_int,sqlite3_bind_int64, | 3_2_609256E5 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094B6ED sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step, | 3_2_6094B6ED |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6092562A sqlite3_bind_blob, | 3_2_6092562A |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60925655 sqlite3_bind_null,sqlite3_mutex_leave, | 3_2_60925655 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094C64A sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free, | 3_2_6094C64A |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_609687A7 sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_column_int64,sqlite3_reset,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free, | 3_2_609687A7 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095F7F7 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset, | 3_2_6095F7F7 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6092570B sqlite3_bind_double,sqlite3_mutex_leave, | 3_2_6092570B |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095F772 sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, | 3_2_6095F772 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60925778 sqlite3_bind_value,sqlite3_bind_int64,sqlite3_bind_double,sqlite3_bind_blob, | 3_2_60925778 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6090577D sqlite3_bind_parameter_name, | 3_2_6090577D |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094B764 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step, | 3_2_6094B764 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6090576B sqlite3_bind_parameter_count, | 3_2_6090576B |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094A894 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset, | 3_2_6094A894 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095F883 sqlite3_bind_int64,sqlite3_bind_int,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, | 3_2_6095F883 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094C8C2 sqlite3_value_int,sqlite3_value_int,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_null,sqlite3_bind_null,sqlite3_step,sqlite3_reset, | 3_2_6094C8C2 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096281E sqlite3_mprintf,sqlite3_vtab_config,sqlite3_malloc,sqlite3_mprintf,sqlite3_mprintf,sqlite3_errmsg,sqlite3_mprintf,sqlite3_free,sqlite3_mprintf,sqlite3_exec,sqlite3_free,sqlite3_prepare_v2,sqlite3_bind_text,sqlite3_step,sqlite3_column_int64,sqlite3_finalize,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_errmsg,sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_free,sqlite3_mprintf,sqlite3_free,sqlite3_declare_vtab,sqlite3_errmsg,sqlite3_mprintf,sqlite3_free, | 3_2_6096281E |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6096583A memcmp,sqlite3_realloc,qsort,sqlite3_malloc,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_step,sqlite3_reset, | 3_2_6096583A |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095F9AD sqlite3_bind_int,sqlite3_step,sqlite3_column_type,sqlite3_reset, | 3_2_6095F9AD |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6094A92B sqlite3_bind_int64,sqlite3_bind_null,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, | 3_2_6094A92B |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6090EAE5 sqlite3_transfer_bindings, | 3_2_6090EAE5 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095FB98 sqlite3_value_int,sqlite3_bind_int,sqlite3_bind_value,sqlite3_step,sqlite3_reset, | 3_2_6095FB98 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095ECA6 sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_bind_value, | 3_2_6095ECA6 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095FCCE sqlite3_malloc,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset, | 3_2_6095FCCE |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095FDAE sqlite3_malloc,sqlite3_bind_int,sqlite3_step,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_bind_int,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,sqlite3_free, | 3_2_6095FDAE |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60966DF1 sqlite3_value_text,sqlite3_mprintf,sqlite3_free,strcmp,sqlite3_free,sqlite3_malloc,sqlite3_bind_int64,sqlite3_step,sqlite3_column_type,sqlite3_reset,sqlite3_column_blob,sqlite3_reset,sqlite3_malloc,sqlite3_free,sqlite3_reset,sqlite3_result_error_code,sqlite3_result_blob, | 3_2_60966DF1 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_60969D75 sqlite3_bind_int,sqlite3_step,sqlite3_column_int,sqlite3_reset, | 3_2_60969D75 |
Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe | Code function: 3_2_6095FFB2 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_result_error_code, | 3_2_6095FFB2 |