Windows Analysis Report
Standard_Monitor_Driver_Signed_Win10_x64.exe

Overview

General Information

Sample Name: Standard_Monitor_Driver_Signed_Win10_x64.exe
Analysis ID: 882704
MD5: cf77f6850ff98d1b681832160f2691fe
SHA1: ccba9f71b67bd9582804b6a3c27fbcf89431e7be
SHA256: d81e3afb0a8a83be2f99c5709d2b107171dc86b33405729fbef539bba4449de1
Infos:

Detection

Score: 5
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Drops certificate files (DER)
Contains functionality to shutdown / reboot the system
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
PE file contains sections with non-standard names
Detected potential crypto function
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to dynamically determine API calls
Found dropped PE file which has not been started or loaded
Contains functionality which may be used to detect a debugger (GetProcessHeap)
PE file contains executable resources (Code or Archives)
Creates a DirectInput object (often for capturing keystrokes)
Drops files with a non-matching file extension (content does not match file extension)
Sample file is different than original file name gathered from version info
Extensive use of GetProcAddress (often used to hide API calls)
Drops PE files
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)

Classification

Source: Standard_Monitor_Driver_Signed_Win10_x64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe Static PE information: certificate valid
Source: Binary string: C:\Program Files\Microsoft Visual Studio\MyProjects\test_dll\Debug\test_dll.pdb source: IKernel.exe, 00000003.00000003.484014175.0000000002B08000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: devcon.pdb source: devcon.exe, 00000007.00000002.487172347.0000000100001000.00000020.00000001.01000000.00000010.sdmp, devcon.exe, 00000007.00000000.486540487.0000000100001000.00000020.00000001.01000000.00000010.sdmp, devcon.exe, 0000000C.00000000.567162701.0000000100001000.00000020.00000001.01000000.00000010.sdmp, devcon.exe, 0000000C.00000002.567616238.0000000100001000.00000020.00000001.01000000.00000010.sdmp
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_004014C2 wsprintfA,FindFirstFileA,FindClose, 0_2_004014C2
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_004050D5 lstrcpyA,lstrcpyA,lstrcatA,lstrcatA,DeleteFileA,DeleteFileA,FindFirstFileA,lstrcpyA,lstrcatA,lstrcatA,lstrcpyA,lstrcatA,DeleteFileA,FindNextFileA,FindClose,lstrcpyA,lstrlenA,RemoveDirectoryA, 0_2_004050D5
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00458620 CreateEventA,GetProcAddress,SearchPathA,GetModuleFileNameA,FindFirstFileA,VirtualProtect,VirtualQuery,VirtualProtect,VirtualProtect,FindClose,FindClose, 2_2_00458620
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00428EA6 __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose, 2_2_00428EA6
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00429025 __EH_prolog,FindFirstFileA,FileTimeToLocalFileTime,FileTimeToDosDateTime,FindNextFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, 2_2_00429025
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0042A298 __EH_prolog,FindFirstFileA,FindClose, 2_2_0042A298
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0045256E __EH_prolog,FindFirstFileA,FindNextFileA,FindNextFileA,FindNextFileA,FindClose, 2_2_0045256E
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0045A9E4 __EH_prolog,FindFirstFileA,FindClose,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose,RemoveDirectoryA,FindClose,DeleteFileA, 2_2_0045A9E4
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0044ACA8 __EH_prolog,FindFirstFileA,FindNextFileA,SafeArrayCopy,FindClose, 2_2_0044ACA8
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0044B21F __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,SafeArrayCopy,FindClose, 2_2_0044B21F
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\Local\Temp\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0=
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://ocsp.digicert.com0
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://ocsp.digicert.com0A
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://ocsp.digicert.com0C
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://ocsp.digicert.com0X
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe String found in binary or memory: http://www.digicert.com/CPS0
Source: IKernel.exe, 00000003.00000003.581439915.0000000002AF3000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.580553661.0000000002ADB000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.installuser.com/user/
Source: IKernel.exe, 00000003.00000003.533702562.0000000002B1B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.viewsonic.com
Source: IKernel.exe, 00000003.00000003.515919292.0000000002B1B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.viewsonic.com.cn
Source: IKernel.exe, 00000003.00000003.519124556.0000000002B1B000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.515919292.0000000002B1B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.viewsonic.com.cndesc
Source: IKernel.exe, 00000003.00000003.533702562.0000000002B1B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.viewsonic.comXYZ
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00458869 InternetReadFile,SetLastError, 2_2_00458869
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe, 00000000.00000002.611349795.00000000004FB000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\sd-t245.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx321e94.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp23d269.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va162e34.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va27350a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va27f4d5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg3202-c.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td27dc6b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td24fca5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va342412.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\pjd5d854.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va325748.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg325cc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg322b46.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2418b8.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va19f7c3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24ef4.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2370_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2261_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg279e3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp27158.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx242ea1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2349_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2785d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va95e1d9.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp34131b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24279d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx242923.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va19d2d5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va20e880.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2719-2k_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td161b77.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\sd-te0df.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24e275.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg322ae8.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\VX3217-FHD.inf (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24253b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va19918.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2417fd.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2719f1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\sd-z246.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx271e36.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2750a1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg24ec68.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg2702_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\pjd8d46c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg2401 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg22496d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va3257d4.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vs224a96.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx271d9a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2753_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2257.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg27127e.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2714a1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24fc66.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx27ce80.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp241f8e.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg25ff54.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg32f9e5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va221127.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp3881.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td2240_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx27de30.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg24474a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx32763.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td2210_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx27567d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2721ef.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2410_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2420f5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx3249cb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2256_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2713a7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx23ce22.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp2410b9.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg27185a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\sd-t225.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va223b25.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va221731.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp27d1ad.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va91d110.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td22dd65.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2452_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va27d9da.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td23d1db.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp23d268.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp27aae.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\sd-z225.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx32bb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vs223d19.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va22cc8c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\pjd5134.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2376_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2363_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2449_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx244873.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24f949.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va70dc2c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va27d6d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2756_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va28e10e.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24fd9f.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg3448e0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va244fb6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va272635.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\sd-ze39e.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg272a4c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va271aac.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx3217-fhd.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx24fe99.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx274d84.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx32fec7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2770_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2276_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx22f5cf.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx3258_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx3208_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2235_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx3218_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2747b7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg24153d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va23d94e.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24e312.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2401_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2732b8.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx23df87.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg27bd7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg20daa5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2732_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg27ecc6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2428c5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2037 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg27ec5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2445c3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24e39.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp2716c4.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp2780_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2435_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg2402 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2426a3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg323d8.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx274b9f.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg27213.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\VX3256f.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx271d0d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va23cdc5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2929ee.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va916_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx241637.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2448.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg27108a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2880_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg322cad.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2476_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2407_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va19deeb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg27ed33.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp382de.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2233c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg271983.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx174ce7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx3258de.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2433mh_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx242991.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg27fb6c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va19d239.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx272376.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2039.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx24e65d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx245842.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2754b7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp244e4f.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg27fd02.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td22f8eb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td2439ec.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp2785-4k.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va221184.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va244815.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2855_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx23f532.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx43fdfc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2443ef.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx3211-2k_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\VX3217_QHD.inf (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2755b1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg253316.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24e3fc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2451_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg24f61.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va20d4f8.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\VX275295.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg351221.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp272d0b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx245544.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2359 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2427fa.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vs2425a9.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx4380_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg22985.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg22ceed.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\pjd6d68f.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp2770_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24178f.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td241b19.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24475.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va1630_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx3211 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td2430 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td22f561.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx32b79.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2742c6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va22f726.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx28e053.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2765_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va164d2.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2759 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va274f1a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp273067.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va19dcc8.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td16fbf.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td17b0c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24d084.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx32fe2b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx24a51.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24407.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va20ebdc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2449 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2239_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2022_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\VX3276-QHD.inf (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td2340_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2440c2.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\id2435d5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2439_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va247c0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\pjd5234.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp24f65b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td2230_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\sd-zd3a1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va22f14a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va23f6c9.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg3220_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx22e91d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va20cfe7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va19e498.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2037a-led-2.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx321f30.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va1917_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va1920_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2756da.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp164ebc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx32697.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24513d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx282fca.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va242858.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2214s_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2431ed.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24fc08.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2342_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2456_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va705_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2746_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2446ae.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vs2414d0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2751aa.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx27eff3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va22da09.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg27cb63.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va951s.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va222f6d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg27448b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24fb3d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx275360.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg27224d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va22e7b5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg22e208.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va244229.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2201_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx24dbce.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg253410.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2453_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\VX326f5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg272c40.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va275e.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg2730 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va274621.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2241_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx271695.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24e024.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx321443.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24d5f2.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg24281.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp3268-4k.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg27ea.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg22fadf.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp2468_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td2713e6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va244362.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg2701 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2233smh_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2455_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg161be5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx24d8b1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2445_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp32fff0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\pjd5d75a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg2530 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2248.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx271925.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24cf1c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2259 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va1901_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va1921_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va272700.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2459_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td242182.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp2775.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg3240c_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg344517.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\sd-te17b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2419_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg27159b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va228ba.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\pjd6543w.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx275208.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg242bb3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va271c71.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va241a4e.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2253_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2055_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg2700-4k.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va24edc0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp27e506.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td3224ed.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg22de8d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va1948_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp2365_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va1938_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2778_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg27541b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va222318.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va1922-a.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg2433smh_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vg24102d.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\pjd8353s.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx321b5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\td2740_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp27ca2.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va22d00.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2265_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg322eff.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\xg27202a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vx2475 series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va2756_series.cat (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp27fa82.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp344df1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\va224af3.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\ViewSonic\vp272d79.rra Jump to dropped file
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00442FC7 __EH_prolog,SysAllocString,SysFreeString,WritePrivateProfileStringA,GetVersionExA,RegCreateKeyExA,RegQueryValueExA,wsprintfA,lstrcpyA,lstrlenA,RegSetValueExA,RegCloseKey,ExitWindowsEx,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx, 2_2_00442FC7
Source: C:\Windows\SysWOW64\cmd.exe File created: C:\Windows\SysWOW64\mon.txt Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_004124E8 0_2_004124E8
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_0040FD34 0_2_0040FD34
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_0040D3CF 0_2_0040D3CF
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_0040F7D6 0_2_0040F7D6
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_004600B0 2_2_004600B0
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00454689 2_2_00454689
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00462482 2_2_00462482
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: String function: 0045C1CC appears 748 times
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: String function: 0045BBB5 appears 49 times
Source: temp.000.1.dr Static PE information: Resource name: PUBLICKEY type: b.out overlay separate pure segmented executable V2.3 186 286 286 386 Large Text Large Data Huge Objects Enabled
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe, 00000000.00000002.611272875.000000000041A000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenamestub32i.exe vs Standard_Monitor_Driver_Signed_Win10_x64.exe
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe Binary or memory string: OriginalFilenamestub32i.exe vs Standard_Monitor_Driver_Signed_Win10_x64.exe
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File read: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Jump to behavior
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process created: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe" -RegServer
Source: unknown Process created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe C:\PROGRA~2\COMMON~1\INSTAL~1\user\6\INTEL3~1\IKernel.exe -Embedding
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\iKernel.exe" /REGSERVER
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon find monitor\* > mon.txt
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon.exe C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon find monitor\*
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon update
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon.exe C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon update
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process created: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe" -RegServer Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\iKernel.exe" /REGSERVER Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon find monitor\* > mon.txt Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon update Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon.exe C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon find monitor\* Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon.exe C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon update
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00442FC7 __EH_prolog,SysAllocString,SysFreeString,WritePrivateProfileStringA,GetVersionExA,RegCreateKeyExA,RegQueryValueExA,wsprintfA,lstrcpyA,lstrlenA,RegSetValueExA,RegCloseKey,ExitWindowsEx,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx, 2_2_00442FC7
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File created: C:\Users\user\AppData\Local\Temp\plfAF50.tmp Jump to behavior
Source: classification engine Classification label: clean5.winEXE@18/1146@0/0
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Code function: 1_2_00405F89 lstrcpyA,__setjmp3,CoCreateInstance,CoCreateInstance,Sleep,CoCreateInstance, 1_2_00405F89
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe File read: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.ini Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_00405C6C GetModuleHandleA,GetProcAddress,lstrcpyA,lstrcatA,GetDiskFreeSpaceExA,GetLastError,GetDiskFreeSpaceA, 0_2_00405C6C
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_00402388 GetLastError,FormatMessageA, 0_2_00402388
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1772:120:WilError_01
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7160:120:WilError_01
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_00405416 FindResourceA,LoadResource,LockResource,LocalAlloc,CreatePalette,LocalFree, 0_2_00405416
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\ Jump to behavior
Source: Setup.exe String found in binary or memory: -InstallShield
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File written: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.ini Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Windows\SysWOW64\RICHED32.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe Static file information: File size 3593536 > 1048576
Source: Standard_Monitor_Driver_Signed_Win10_x64.exe Static PE information: certificate valid
Source: Binary string: C:\Program Files\Microsoft Visual Studio\MyProjects\test_dll\Debug\test_dll.pdb source: IKernel.exe, 00000003.00000003.484014175.0000000002B08000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: devcon.pdb source: devcon.exe, 00000007.00000002.487172347.0000000100001000.00000020.00000001.01000000.00000010.sdmp, devcon.exe, 00000007.00000000.486540487.0000000100001000.00000020.00000001.01000000.00000010.sdmp, devcon.exe, 0000000C.00000000.567162701.0000000100001000.00000020.00000001.01000000.00000010.sdmp, devcon.exe, 0000000C.00000002.567616238.0000000100001000.00000020.00000001.01000000.00000010.sdmp
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_00408928 push eax; ret 0_2_00408946
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_004081B0 push eax; ret 0_2_004081DE
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Code function: 1_2_00407AB0 push eax; ret 1_2_00407ADE
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0045C1CC push eax; ret 2_2_0045C1EA
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0045C360 push eax; ret 2_2_0045C38E
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00406AAF push esp; ret 2_2_00406ABE
Source: objebdb7.rra.3.dr Static PE information: section name: .orpc
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_00405DF9 LoadLibraryA,GetProcAddress,lstrlenA,lstrlenA,lstrlenA, 0_2_00405DF9
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\temp.000 Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\ctorbcec.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\objebdb7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\iusebde6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscrbeb1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcc23b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsUc299.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\isrtc335.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsRc3c2.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\Setucb05.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\Setup.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File created: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\isrtc335.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsUc299.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\Setucb05.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsUser.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\temp.000 Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\iusebde6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscript.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcc23b.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsRc3c2.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\ctorbcec.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\objebdb7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\ctor.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\objectps.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\isrt.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\iuser.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsRes.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscrbeb1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00458426 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 2_2_00458426
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\isrtc335.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsUc299.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsUser.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\iusebde6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsRc3c2.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\ctorbcec.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\objebdb7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\isrt.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\_IsRes.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscrbeb1.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe API coverage: 7.2 %
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_004014C2 wsprintfA,FindFirstFileA,FindClose, 0_2_004014C2
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_004050D5 lstrcpyA,lstrcpyA,lstrcatA,lstrcatA,DeleteFileA,DeleteFileA,FindFirstFileA,lstrcpyA,lstrcatA,lstrcatA,lstrcpyA,lstrcatA,DeleteFileA,FindNextFileA,FindClose,lstrcpyA,lstrlenA,RemoveDirectoryA, 0_2_004050D5
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00458620 CreateEventA,GetProcAddress,SearchPathA,GetModuleFileNameA,FindFirstFileA,VirtualProtect,VirtualQuery,VirtualProtect,VirtualProtect,FindClose,FindClose, 2_2_00458620
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00428EA6 __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose, 2_2_00428EA6
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00429025 __EH_prolog,FindFirstFileA,FileTimeToLocalFileTime,FileTimeToDosDateTime,FindNextFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, 2_2_00429025
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0042A298 __EH_prolog,FindFirstFileA,FindClose, 2_2_0042A298
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0045256E __EH_prolog,FindFirstFileA,FindNextFileA,FindNextFileA,FindNextFileA,FindClose, 2_2_0045256E
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0045A9E4 __EH_prolog,FindFirstFileA,FindClose,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose,RemoveDirectoryA,FindClose,DeleteFileA, 2_2_0045A9E4
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0044ACA8 __EH_prolog,FindFirstFileA,FindNextFileA,SafeArrayCopy,FindClose, 2_2_0044ACA8
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0044B21F __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,SafeArrayCopy,FindClose, 2_2_0044B21F
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\Setup.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\Local\Temp\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\Local\Temp\pftB01D.tmp\Disk1\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\ Jump to behavior
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: IKernel.exe, 00000002.00000002.478696566.00000000004DA000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000002.596635353.00000000031CA000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000004.00000002.483352029.0000000000685000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_00405DF9 LoadLibraryA,GetProcAddress,lstrlenA,lstrlenA,lstrlenA, 0_2_00405DF9
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_004061FB GetProcessHeap,HeapAlloc, 0_2_004061FB
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_0040CC52 SetUnhandledExceptionFilter, 0_2_0040CC52
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_0040CC64 SetUnhandledExceptionFilter, 0_2_0040CC64
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0045E8EA SetUnhandledExceptionFilter, 2_2_0045E8EA
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_0045E8FC SetUnhandledExceptionFilter, 2_2_0045E8FC
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon find monitor\* > mon.txt Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon update Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon.exe C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon find monitor\* Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon.exe C:\Users\user\AppData\Local\Temp\{FC47C7A5-BE63-11D5-B7C9-005004566E4D}\devcon update
Source: IKernel.exe, 00000003.00000003.594730884.000000000052E000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.593233905.000000000052D000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.582202380.000000000052C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMAN_FIE
Source: IKernel.exe, IKernel.exe, 00000003.00000003.580961365.000000000055E000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.581127560.0000000000569000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.581038360.0000000000563000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMAN
Source: Setup.exe, 00000001.00000003.476837151.00000000005F8000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.476855656.0000000000600000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.588248372.000000000063C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMAN_FIELDS
Source: Setup.exe, 00000001.00000003.476837151.00000000005F8000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.476855656.0000000000600000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.588248372.000000000063C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMAN_FIELDS%H
Source: IKernel.exe, 00000003.00000003.594730884.000000000052E000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.593233905.000000000052D000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.582202380.000000000052C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMAN_FIES%H
Source: IKernel.exe, 00000003.00000003.592543663.000000000056C000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.590699438.000000000056C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: BOPTYPE_PROGMAN
Source: IKernel.exe, 00000003.00000003.592543663.000000000056C000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.580961365.000000000055E000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.581127560.0000000000569000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: B`OPTYPE_PROGMAN
Source: IKernel.exe, 00000002.00000000.477202457.0000000000482000.00000008.00000001.01000000.00000007.sdmp, IKernel.exe, 00000002.00000002.478628673.0000000000482000.00000008.00000001.01000000.00000007.sdmp, IKernel.exe, 00000003.00000002.595604396.0000000000482000.00000004.00000001.01000000.00000007.sdmp Binary or memory string: ISGlobalOpTypesTableISLOG_VERSION_INFOOPTYPE_FILEOPTYPE_SHELLOPTYPE_REGISTRYOPTYPE_PROGMANOPTYPE_INIOPTYPE_FILEREGISLOGDB_USER_PROPERTIES
Source: C:\Windows\SysWOW64\cmd.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Queries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Common Files\InstallShield\user\6\Intel 32\IKernel.exe Code function: 2_2_00429477 GetSystemTime,SystemTimeToFileTime,SystemTimeToFileTime,SystemTimeToFileTime, 2_2_00429477
Source: C:\Users\user\Desktop\Standard_Monitor_Driver_Signed_Win10_x64.exe Code function: 0_2_00408947 EntryPoint,GetVersion,GetCommandLineA,GetStartupInfoA,GetModuleHandleA, 0_2_00408947
No contacted IP infos