Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: wbemcomn.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: vaultcli.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: rasapi32.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: rasman.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: rtutils.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1200000 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199890 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199781 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199671 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199562 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199453 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199343 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199234 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199125 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199015 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198906 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198796 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198687 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198577 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198468 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198359 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198249 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198140 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198030 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197921 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197802 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197683 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197562 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197452 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197343 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197209 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197093 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196984 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196874 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196765 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196656 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196546 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196437 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196328 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196218 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196109 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196000 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195890 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195781 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195671 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195562 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195453 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195343 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195219 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195059 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194953 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194843 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194734 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194624 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194515 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1200000 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199874 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199765 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199656 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199546 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199437 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199328 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199218 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199109 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198999 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198890 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198662 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198531 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198421 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198312 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198202 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198092 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197984 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197874 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197765 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197655 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197546 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197429 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197312 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197203 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197093 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196984 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196874 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196764 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196656 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196546 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196437 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196328 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196218 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196109 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195999 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195888 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195781 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195671 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195562 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195453 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195343 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195234 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195124 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195014 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194906 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194796 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194687 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194559 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194452 | |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 1896 | Thread sleep time: -1844674407370954s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 6400 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4024 | Thread sleep time: -7378697629483816s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5596 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5304 | Thread sleep time: -4611686018427385s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6180 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep count: 41 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -37815825351104557s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1200000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 5772 | Thread sleep count: 3000 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1199890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1199781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1199671s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1199562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1199453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1199343s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 5772 | Thread sleep count: 6854 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1199234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1199125s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1199015s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1198906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1198796s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1198687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1198577s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1198468s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1198359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1198249s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1198140s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1198030s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1197921s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1197802s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1197683s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1197562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1197452s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1197343s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1197209s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1197093s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196874s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196765s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1196000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1195890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1195781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1195671s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1195562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1195453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1195343s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1195219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1195059s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1194953s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1194843s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1194734s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1194624s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe TID: 4508 | Thread sleep time: -1194515s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 6504 | Thread sleep time: -5534023222112862s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 2576 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep count: 34 > 30 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -31359464925306218s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1200000s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1199874s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 2360 | Thread sleep count: 7411 > 30 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 2360 | Thread sleep count: 2449 > 30 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1199765s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1199656s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1199546s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1199437s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1199328s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1199218s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1199109s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1198999s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1198890s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1198662s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1198531s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1198421s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1198312s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1198202s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1198092s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1197984s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1197874s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1197765s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1197655s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1197546s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1197429s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1197312s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1197203s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1197093s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1196984s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1196874s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1196764s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1196656s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1196546s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1196437s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1196328s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1196218s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1196109s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195999s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195888s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195781s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195671s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195562s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195453s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195343s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195234s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195124s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1195014s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1194906s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1194796s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1194687s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1194559s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe TID: 5820 | Thread sleep time: -1194452s >= -30000s | |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1200000 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199890 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199781 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199671 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199562 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199453 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199343 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199234 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199125 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1199015 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198906 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198796 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198687 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198577 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198468 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198359 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198249 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198140 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1198030 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197921 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197802 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197683 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197562 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197452 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197343 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197209 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1197093 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196984 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196874 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196765 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196656 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196546 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196437 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196328 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196218 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196109 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1196000 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195890 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195781 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195671 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195562 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195453 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195343 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195219 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1195059 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194953 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194843 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194734 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194624 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Thread delayed: delay time: 1194515 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1200000 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199874 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199765 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199656 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199546 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199437 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199328 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199218 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1199109 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198999 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198890 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198662 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198531 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198421 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198312 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198202 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1198092 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197984 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197874 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197765 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197655 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197546 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197429 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197312 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197203 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1197093 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196984 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196874 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196764 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196656 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196546 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196437 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196328 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196218 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1196109 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195999 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195888 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195781 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195671 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195562 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195453 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195343 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195234 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195124 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1195014 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194906 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194796 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194687 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194559 | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Thread delayed: delay time: 1194452 | |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Users\user\Desktop\hesaphareketi-.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Users\user\Desktop\hesaphareketi-.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi-.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\xyodEPhulIrkY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | |