Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\SysWOW64\ws2_32.dlll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.VCLibs.140.00.UWPDesktop_14.0.30704.0_x64__8wekyb3d8bbwe\MSVCP140_1.dll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9635_none_508ff82ebcbafee0\msvcp90.dll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\System32\UXInit.dlldllp |
Source: 3498_ED6E000.dll | Binary string: 4\Device\HarddiskVolume3\Windows\System32\perfTMP.dat |
Source: 3498_ED6E000.dll | Binary string: +3\Device\HarddiskVolume3\Windows\SysWOW64\oledlg.dll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9635_none_508ff82ebcbafee0\msvcm90.dll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\internal-deps\dvt\thematicMap\basemaps\resourceBundles\UsaCountiesBundle_pl.js |
Source: 3498_ED6E000.dll | Binary string: :\Device\HarddiskVolume3\Empower\Instr$ |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsTerminal_1.12.10983.0_x64__8wekyb3d8bbwe\Microsoft.Terminal.Control.dll |
Source: 3498_ED6E000.dll | Binary string: 7\Device\HarddiskVolume3\Windows\System32\TaskSchdPS.dll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Instr$ |
Source: 3498_ED6E000.dll | Binary string: D\Device\HarddiskVolume3\Windows\System32\CapabilityAccessManager.dll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\flashchart\anychart_6\swf\maps\usa\regions\states\northeast.amap |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\internal-deps\dvt\thematicMap\basemaps\resourceBundles\UsaCountiesBundle_pt.js |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\internal-deps\dvt\thematicMap\basemaps\resourceBundles\UsaCountiesBundle_ro.js |
Source: 3498_ED6E000.dll | Binary string: J\Device\HarddiskVolume3\Windows\System32\Windows.StateRepositoryClient.dll |
Source: 3498_ED6E000.dll | Binary string: +R\Device\HarddiskVolume3\Windows\assembly\GAC_MSIL\Waters.WFMA.ConsoleFMA.resources |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\internal-deps\dvt\thematicMap\basemaps\resourceBundles\UsaCountiesBundle_sk.js |
Source: 3498_ED6E000.dll | Binary string: +R\Device\HarddiskVolume3\Windows\assembly\GAC_MSIL\Waters.WFMA.EmpowerFMA.resources |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsTerminal_1.12.10983.0_x64__8wekyb3d8bbwe\Microsoft.Terminal.Settings.Editor.dll |
Source: 3498_ED6E000.dll | Binary string: p\Device\HarddiskVolume3\Windows\System32\tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\System32\UXInit.dll |
Source: 3498_ED6E000.dll | Binary string: 5\Device\HarddiskVolume3\Windows\System32\rundll32.exe |
Source: 3498_ED6E000.dll | Binary string: .:\Device\Ha8 |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\internal-deps\dvt\thematicMap\basemaps\resourceBundles\UsaCountiesBundle_nl.js |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Program Files (x86)\Waters\ICSp |
Source: 3498_ED6E000.dll | Binary string: +D\Device\HarddiskVolume3\Empower\Instruments\Bin\AcquityISMCommon.dll |
Source: 3498_ED6E000.dll | Binary string: \device\asrdrv\dosdevices\asrdrv\device\asusgio\dosdevices\asusgio\device\asupdateio\dosdevices\asupdateio\device\glckio\dosdevices\glckio\device\gio\dosdevices\gio\device\gvcidrv\dosdevices\gvcidrv\device\msio\dosdevices\msio\device\ntiolib\dosdevices\ntiolib\device\semav6msr\dosdevices\semav6msr\device\{f0e8ccf6-5232-4b6f-a159-3b612b77a43f}\dosdevices\{f0e8ccf6-5232-4b6f-a159-3b612b77a43f}\device\atikia\dosdevices\atikia\device\atillk\dosdevices\atillk\device\bs_hwmio\dosdevices\bs_hwmio\device\bs_i2cio\dosdevices\bs_i2cio\device\bsmem\dosdevices\bsmem\device\bsmi\??\bsmi\device\wnbios\dosdevices\wnbios\device\hwos2ecdev\dosdevices\hwos2ec\device\mtc0303\dosdevices\mtc0303\device\nchgbios\dosdevices\nchgbios\device\genericdrv\??\genericdrv\device\bs_flash\dosdevices\bs_flash\device\nvflash\dosdevices\nvflash\device\winphlash\dosdevices\winphlash\device\phymem\dosdevices\phymem\device\piddrv\dosdevices\piddrv\device\pmxdrv\dosdevices\pmxdrv\device\ucorew\??\ucorew\device\winflash\dosdevices\winflash\device\rtkio\dosdevices\rtkio\device\superbmc0\dosdevices\superbmc\device\winring0\dosdevices\winring0d:\svn\cheat engine\bin\dbk64.pdbh |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Program Files (xomtmall.comlist.tmall.comtmall.comneiyi.tmall.comtmall.comshouji.tmall.comtmall.comwww.tmall.com!#EsrpVulDrv |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\System32\dusmsvc.dll |
Source: 3498_ED6E000.dll | Binary string: +s\Device\HarddiskVolume3\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9635_none_508ff82ebcbafee0 |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\ |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.UI.Xaml.2.7_7.2203.17001.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\oracore\zoneinfo\timezone_16.dat |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db-shm |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\librarRCRD( |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-ARIA-5476d0c4a7a347909c4b8a13078d4390-f8bdcecf-243f-40f8-b7c3-b9c44a57dead-7230.json |
Source: 3498_ED6E000.dll | Binary string: 4\Device\HarddiskVolume3\Windows\System32\svchost.exe |
Source: 3498_ED6E000.dll | Binary string: \device\tmcomm\dosdevices\tmcomm!#HSTR:DelfCPLException |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-a..ence-mitigations-c8_31bf3856ad36 |
Source: 3498_ED6E000.dll | Binary string: ;\Device\HarddiskVolume3\Empower\Instr$ |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\nls\kok\localeElements.js |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9635_none_508ff82ebcbafee0\msvcr90.dll |
Source: 3498_ED6E000.dll | Binary string: +E\Device\HarddiskVolume3\Empower\Instruments\Bin\AcquityISMEditMgr.ocx |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\security\EDP\Logsdll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-a..ence-mitigations-c8_31bf3856ad364e35_10.0.22621.457_none_6e3a8cbbbb69623c |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\internal-deps\dvt\thematicMap\basemaps\resourceBundles\UsaCountiesBundle_ru.js |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Program FilFILE0 |
Source: 3498_ED6E000.dll | Binary string: M\Device\HarddiskVolume3\Windows\System32\tasks\Microsoft\Windows\Work Folders |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\nls\kok\timezoneData.js |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.VCLibs.140.00.UWPDesktop_14.0.30704.0_x64__8wekyb3d8bbwe\msvcp140_1.dll |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db-wal |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\nls\ks\localeElements.js |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\flashchart\anychart_6\swf\maps\south_america\french_guiana.amap |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\nls\ko-KR\timezoneData.js |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\TenantStorage\P-ARIA\EventStore.db |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Windows\SysWOW64\twinapi.appcore.dlldll4te |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\libraries\oraclejet\4.2.0\js\libs\oj\v4.2.0\resources\internal-deps\dvt\thematicMap\basemaps\resourceBundles\UsaCountiesBundle_pt_BR.js |
Source: 3498_ED6E000.dll | Binary string: =\Device\HarddiskVolume3\Windows\System32\WorkFoldersShell.dll |
Source: 3498_ED6E000.dll | Binary string: /\Device\HarddiskVolume3\Windows\System32\sc.exe |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Empower\Oracle\Oracle18c\apex\images\librarRCRD( |
Source: 3498_ED6E000.dll | Binary string: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsTerminal_1.12.10983.0_x64__8wekyb3d8bbwe\Microsoft.Terminal.Control.dll$ |