Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: unknown | Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe "C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe" |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe "C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe" |
Source: C:\Windows\System32\rundll32.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 428 -p 7080 -ip 7080 |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7080 -s 564 |
Source: C:\Windows\SysWOW64\WerFault.exe | Process created: unknown unknown |
Source: unknown | Process created: C:\Program Files\7-Zip\7zG.exe "C:\Program Files\7-Zip\7zG.exe" x -o"C:\Users\user\Desktop\WebReport_safe_certified_2024\" -spe -an -ai#7zMap25386:114:7zEvent4983 |
Source: unknown | Process created: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe "C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe" |
Source: unknown | Process created: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe "C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe" |
Source: unknown | Process created: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe "C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe" |
Source: unknown | Process created: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe "C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe" |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: version.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: netapi32.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: netutils.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: uxtheme.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: wtsapi32.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: winsta.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: textshaping.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: textinputframework.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: coreuicomponents.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: coremessaging.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: ntmarta.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Section loaded: wintypes.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: kernel.appcore.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: uxtheme.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: cryptbase.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: explorerframe.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: textshaping.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: textinputframework.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: coreuicomponents.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: coremessaging.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: ntmarta.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: wintypes.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: wintypes.dll |
Source: C:\Program Files\7-Zip\7zG.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: version.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: netapi32.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: netutils.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: wtsapi32.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: winsta.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: textshaping.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: textinputframework.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: coreuicomponents.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: coremessaging.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: ntmarta.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: dwmapi.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: version.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: netapi32.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: netutils.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: wtsapi32.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: winsta.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: textshaping.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: textinputframework.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: coreuicomponents.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: coremessaging.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: ntmarta.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Section loaded: dwmapi.dll |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\Temp1_WebReport_safe_certified_2024.zip\regAgent.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\WebReport_safe_certified_2024\regAgent.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |