Source: unknown |
Process created: C:\Users\user\Desktop\ptKNiAaGus.exe "C:\Users\user\Desktop\ptKNiAaGus.exe" |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\wbem\WmiPrvSE.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Avast Antivirus" /tr "C:\Users\user\xdwdPutty.exe" & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Avast Antivirus" /tr "C:\Users\user\xdwdPutty.exe" |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo 5 /tn "Google Drive" /tr "C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c start /b powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe"' & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo 5 /tn "Google Drive" /tr "C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe"' |
|
Source: unknown |
Process created: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe "C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe" |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe" |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "OpenOffice" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "OpenOffice" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c start /b powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe"' & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe"' |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe" |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Users\user\xdwdPutty.exe "C:\Users\user\xdwdPutty.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Azure DevOps" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Azure DevOps" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" /RL HIGHEST |
|
Source: C:\Users\user\xdwdPutty.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: unknown |
Process created: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe "C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe" |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: unknown |
Process created: C:\Users\user\xdwdPutty.exe C:\Users\user\xdwdPutty.exe |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\xdwdPutty.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: unknown |
Process created: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe "C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe" |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Users\user\xdwdPutty.exe C:\Users\user\xdwdPutty.exe |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Azure DevOps" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" /RL HIGHEST & exit |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo 5 /tn "Corel PaintShop Pro" /tr "C:\Users\user\Videos\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\xdwdPutty.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\conhost.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\schtasks.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\Conhost.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\conhost.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\Conhost.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\conhost.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Avast Antivirus" /tr "C:\Users\user\xdwdPutty.exe" & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo 5 /tn "Google Drive" /tr "C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c start /b powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe"' & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c start /b powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe"' & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Avast Antivirus" /tr "C:\Users\user\xdwdPutty.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo 5 /tn "Google Drive" /tr "C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe" /RL HIGHEST |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe"' |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Users\user\xdwdPutty.exe "C:\Users\user\xdwdPutty.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "OpenOffice" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" & exit |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Azure DevOps" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" /RL HIGHEST & exit |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo 5 /tn "Corel PaintShop Pro" /tr "C:\Users\user\Videos\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "OpenOffice" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe"' |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe" |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Azure DevOps" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\xdwdPutty.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Azure DevOps" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\xdwdPutty.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Users\user\xdwdPutty.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: devenum.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: devobj.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: msdmo.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: netfxperf.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: pdh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: wtsapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: bitsperf.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: bitsproxy.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: esentprf.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: perfts.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: utildll.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: tdh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: samcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: msdtcuiu.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: msdtcprx.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: mtxclu.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: clusapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: resutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: ktmw32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: msscntrs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: perfdisk.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: wmiclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: perfnet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: browcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: perfos.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: perfproc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: sysmain.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: rasctrs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: tapiperf.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: perfctrs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: usbperf.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: tquery.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: cryptdll.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: devenum.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: devobj.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: msdmo.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: twext.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: cscui.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: policymanager.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: msvcp110_win.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: workfoldersshell.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ntshrui.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: windows.fileexplorer.common.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: shacct.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: twinapi.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: idstore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: samlib.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wtsapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wlidprov.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: samcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: provsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: starttiledata.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: usermgrcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: usermgrproxy.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: acppage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: sfc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: msi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: aepic.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: windows.staterepositorycore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: apphelp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: sxs.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: devenum.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: winmm.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: devobj.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: msdmo.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: rasapi32.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: rasman.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: rtutils.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: mswsock.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: winhttp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: ondemandconnroutehelper.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: winnsi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: fwpuclnt.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: secur32.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: schannel.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: mskeyprotect.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: ncryptsslp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: gpapi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: windowscodecs.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: netfxperf.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: pdh.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: wtsapi32.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: bitsperf.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: bitsproxy.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: esentprf.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: perfts.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: winsta.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: utildll.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: tdh.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: samcli.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: netutils.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: msdtcuiu.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: atl.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: msdtcprx.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: mtxclu.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: clusapi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: resutils.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: clusapi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: resutils.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: ktmw32.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: resutils.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: wkscli.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: cscapi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: msscntrs.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: perfdisk.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: wmiclnt.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: perfnet.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: browcli.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: perfos.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: perfproc.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: sysmain.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: umpdc.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: powrprof.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: rasctrs.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: tapiperf.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: perfctrs.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: usbperf.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: tquery.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Section loaded: cryptdll.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edputil.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appresolver.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: bcp47langs.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: slc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sppc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecorecommonproxystub.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: apphelp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: apphelp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: sxs.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: devenum.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: winmm.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: devobj.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: msdmo.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Section loaded: secur32.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: apphelp.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: sxs.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: devenum.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: winmm.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: devobj.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: msdmo.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: secur32.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: sxs.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: devenum.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: winmm.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: devobj.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: msdmo.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: sxs.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: devenum.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: winmm.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: devobj.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: msdmo.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: secur32.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: sxs.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: devenum.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: winmm.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: devobj.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: msdmo.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: amsi.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: sxs.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: devenum.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: winmm.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: devobj.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: msdmo.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\xdwdPutty.exe |
Section loaded: secur32.dll |
|
Source: ptKNiAaGus.exe, BlZVXHIIaPbHfI.cs |
High entropy of concatenated method names: 'tSODIOiBRDXJwkT', 'BJcsukRMTZ', 'wvIinJskLeX', 'eSjHRzyM', 'GAZxDPFJBCj', 'pmFJVkADAIldI', 'ZKcANVNApvikktn', 'KbnSpgexvOxJ', 'yPwpEqvgApO', 'oxKbkAHQZxJ' |
Source: ptKNiAaGus.exe, ngXUOZCVh.cs |
High entropy of concatenated method names: 'SugoyTPgJVvv', 'lWREblyMHEKGgdx', 'wVWJrmsraWSrMU', 'LsgmxwUakjPKpWh', 'qRtNAZmIzd', 'dESGAnJyOArz', 'bulabbDUsFcaSH', 'mFXmUWrWRcPWfXT', 'zSDlFnLhXa', 'kyqghgPL' |
Source: ptKNiAaGus.exe, aTWRcRmMPAC.cs |
High entropy of concatenated method names: 'YWlLHFrhEUxDwZo', 'QNksPVFxWLWn', 'tgWUvohOwiwNQU', 'VSUDcHvC', 'JhDRnoviDs', 'najBlHPTf', 'fzAzbEqTLgxeHK', 'kQaHmNJXJR', 'iTSVrcWadiCRMkE', 'sLMJTYnArp' |
Source: ptKNiAaGus.exe, rEMvqXUYw.cs |
High entropy of concatenated method names: 'KQdgoRhaxzvrrCD', 'ZwAejkTaYkz', 'eUlIvLBnLcIAl', 'ngMAMJrSyYXSO', 'xCHESzwdOmw', 'AQMxoAtxxnNYX', 'qLVNlcwcqIUDim', 'KSZEgJbFBkXZQc', 'ojhcIkHAB', 'kXaDckRHJm' |
Source: ptKNiAaGus.exe, sXNNIwuBLyDCn.cs |
High entropy of concatenated method names: 'KzETmFIz', 'HggOwIlWtJnS', 'fZytGkgFkIg', 'qyHrOJZtuG', 'chytZbKsAjkUf', 'syYTXXYzvGJ', 'efANZeZsWMIq', 'dZPgjFec', 'VKBZXiHdlsj', 'wermKFvmygqhNtx' |
Source: ptKNiAaGus.exe, kiBrAzKlhwI.cs |
High entropy of concatenated method names: '_003CScreenShot_003Eb__16_0', 'GFHyolqxTiPW', 'rTDCGOXiyndD', 'xofGmlAsdGWCitw', 'ABTeMIfH', 'ailvIRdutoBSM', 'eWmNMhAYVadxmKY', 'oIXXMDOwVpsHo', 'vmoFpIZv', 'aiBMLSKeSW' |
Source: ptKNiAaGus.exe, FSmyfmyMutFI.cs |
High entropy of concatenated method names: 'IHADBbEs', 'hQUjjodBxy', 'BVWSWKGm', 'NYnlEwRYEl', 'QmolVevCJjswHEE', 'lihqVSbCIdienW', 'xMDnOgkw', 'OEchVcghzJgpXv', 'yLlcsvQOndv', 'DRqGAlpbQpthg' |
Source: ptKNiAaGus.exe, fJqINigGmUCZC.cs |
High entropy of concatenated method names: 'QlbUeGpFUx', 'olCxFkzEoyLXkt', 'zFJGvZFLDjJBq', 'rZpsSZweJhjCU', 'TFNqauGkwN', 'QiZyOwjJ', 'xYVfRUnVvcX', 'FqsyVSbwaGdcqC', 'WfvlAswRujiZFG', 'pUpJKrhAsdHNw' |
Source: ptKNiAaGus.exe, BsbXIFfqT.cs |
High entropy of concatenated method names: '_003CStart_003Eb__1_0', '_003CUninstall_003Eb__2_0', '_003CLoopInstall_003Eb__7_0', '_003CStartAsBypass_003Eb__10_0', 'UAOIwMuBa', 'mRWRLoTV', 'FiZsYJBwGnrKc', 'UBMyoZKFhorUkV', 'MUlKKOcvH', 'yuQnOiuKZCPypf' |
Source: ptKNiAaGus.exe, nOmJeajqakZQx.cs |
High entropy of concatenated method names: 'VMDOPKelokaHLzt', 'kzXYTmdFAApojK', 'zFhHDuDSU', 'CZBjWOjw', 'zZsZeiiyNOUpB', 'baBdspyhhCSR', 'bVdlGrCKk', 'gCYVvpDA', 'AvaJVkrHiS', 'qGMVHcjcOxyTrU' |
Source: ptKNiAaGus.exe, vJbYblzYrfoB.cs |
High entropy of concatenated method names: 'gFWqIJotzNwvM', 'pfdyvOpMWAXN', 'tmLjgQlSNFQ', 'MEkwwfdOG', 'sNgsnsTiV', 'ulvGndQeaNb', 'NpjJFQaUuyS', 'tyCnctyfkwPbJ', 'ISPyothTzrJe', 'CIAZvTLNpbcChO' |
Source: ptKNiAaGus.exe, AFDAeWnBGIKu.cs |
High entropy of concatenated method names: 'oDwpjjxTMPM', 'PUGJgxszPRRk', 'VAcvknCno', 'JWXeSLLnqrXP', 'hrZLRvHW', 'MfOjUXcbJpaqw', 'ITaoEdbtnGyvDK', 'kshHYJsPjqnK', 'hhoKkDRrrG', 'tJSsIlZU' |
Source: ptKNiAaGus.exe, WBkUEsbhmZeNIv.cs |
High entropy of concatenated method names: 'SoSyVSXfCVs', 'XTskBgXiTfIyZBX', 'UgSMOJxLAaoY', 'WiyMvDNtpchkMCn', 'UZUvtLVCfiNW', 'jbsykxwJldxJk', 'DlbCGKfgATdE', 'MwgMprLGB', 'lcEqWivWlJgSRD', 'GLCCaYVfmkNF' |
Source: ptKNiAaGus.exe, ctLKvSYSpZJt.cs |
High entropy of concatenated method names: 'juxIMOhpgo', 'RdVUgDBImozuSxE', 'gPXRhKdsjiHcVG', 'vENtRwDmmXBHbk', 'fKIaAaIX', 'HAdkywZmfA', 'pFEmsddl', 'gCBHjCwUvGNmhw', 'RSTnqyPcagKZG', 'hXwXekEyVBv' |
Source: ptKNiAaGus.exe, ixSNFcnAZd.cs |
High entropy of concatenated method names: 'yFrqudjmVPGe', 'JkHgNblQEtPkoGd', 'UmYjXsTLRQXsFez', 'TUDUVGmysNtM', 'FGXGoBdivZQR', 'PxDsLatoRUCIcNz', 'qKzGjLKzlQd', 'sXunDYrpvAB', 'TnolVxMndI', 'PRKNDnDH' |
Source: ptKNiAaGus.exe, TJFZgosWeymV.cs |
High entropy of concatenated method names: 'gSupzYBgpZPN', 'IKqmTgAuQrpwBf', 'nGhYugYGHy', 'URudkqMsgigseFV', 'PbFtyslsjrqSH', 'EjoZMiAmGzjJz', 'HODTYxJeCFwbg', 'utAulwew', 'FtnjcVFJ', 'tEkVoXtKaZgjdk' |
Source: ptKNiAaGus.exe, EzwqebyGv.cs |
High entropy of concatenated method names: '_003CPatchMem_003Eb__0', 'XvhDVIDTsz', 'FblPzXsORRWA', 'JozepQtc', 'apucNvwVuq', 'jyYLbeDFsew', 'vethIZdb', 'zpAwVWKx', 'vXfbTLPoDL', 'okmdoyxTOn' |
Source: ptKNiAaGus.exe, ncSubYLaTjDxEKi.cs |
High entropy of concatenated method names: 'HDWwlYrbKQdNSsA', 'esngNPlUUlpm', 'hZZcJBbDb', 'PkqkKvxIa', 'ZSMWBisRCbAjF', 'crElIqYaDj', 'wXebZXdPCkO', 'CaaJJAzIff', 'HSrMzkKyPcy', 'LNpcEWUC' |
Source: ptKNiAaGus.exe, WSBzhPoDCyO.cs |
High entropy of concatenated method names: 'zIwxKQJLlKR', 'qABCbysjh', 'zBiSdHrPVoqvwo', 'hjTaakMApIh', 'lbEFfpGJvP', 'mCUVodUuDMfuPZ', 'HInAsKwtF', 'RiLGpfbSrhYGOX', 'VNeBGhpfWiy', 'uWhqIOhXuJo' |
Source: ptKNiAaGus.exe, YdxQPCPenRPlm.cs |
High entropy of concatenated method names: 'OxDjszrRWVWVc', 'dsDylpVj', 'yDTeALhtU', 'ITqcXHToHG', 'tuaIAuNQzwPf', 'EgZVrFobCHTnnQ', 'qSANchFJsVzQ', 'dURtnDXriyx', 'RArmGVNe', 'ZhvBDFzXgzroU' |
Source: ptKNiAaGus.exe, UfMnWsvflYsaAsK.cs |
High entropy of concatenated method names: 'cSvGSUoqZkIU', 'bDaXGzsPHOnjQl', 'wNlgcmunuLdArVN', 'kboKUSDusSOUE', 'WBiutLybr', 'gQfLczAt', 'bDIbbZeKroKYajm', 'cRxbCoIjkdDmrS', 'RUacEOZHUPBGnh', 'GhsWzhCRrmuY' |
Source: ptKNiAaGus.exe, LyYGZtBCXfhLta.cs |
High entropy of concatenated method names: 'CegapNQcJfAJ', 'AHNZNTemugjcDX', 'vdREkUzXp', 'CcvVObYkKCPSHxa', 'oIxwxlqEggNwYWA', 'YdKqiQfFKstUw', 'WUdnfrZszRmr', 'iNcLoBfudmjOYc', 'mFsVHCJtSkqJLf', 'tDqbwrigESQj' |
Source: ptKNiAaGus.exe, LgUPyuNhoLG.cs |
High entropy of concatenated method names: 'qASorupmplRQ', 'CDYUXuDrC', 'qcrJhNQjBoYVi', 'HcVZjhZODFwrpM', 'QDmoSbLzkI', 'ZCPcmgViMvY', 'IVIbZmNpXDSk', 'lhPNwclQJHXzb', 'PWGzVsYeSK', 'mMWSBVjf' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, YeASamleCu.cs |
High entropy of concatenated method names: 'xnIxVRYrPBFYu', 'bdMoOrQxtvgEAC', 'aaKjZcdK', 'koKrGQSFGdzIY', 'oCRzuMRRQWnpbv', 'VNyTdDahZrdday', 'DvBkWgHcjxR', 'XnDRpWQkPBp', 'nNVsIQjrStTsoqZ', 'OkOVMjCtV' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, BepYSwIiYsKTkc.cs |
High entropy of concatenated method names: '_003CScreenShot_003Eb__16_0', 'hgYqlsJf', 'sLrZOuAb', 'kOWJOWvoQlcxdqy', 'DFyYevrypfGFjUe', 'iYAOjYSCuxcYDC', 'VsaLoCDQoW', 'UiPqEvHkOEq', 'PenvdgTTvmQlM', 'JppfHLrLD' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, gEjezvihrA.cs |
High entropy of concatenated method names: 'SNPMxFexzSMQ', 'gDOlHAunu', 'YzPPDudfl', 'vNRfanEABU', 'TnWxvgwZqFpXCrN', 'paCVmbxQTmjLT', 'umZLELsRHOgGvNG', 'PnNGOazzMspGeJ', 'lGuLDxqnBpYTnog', 'kKdWwyNhUmay' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, WkKaRrezv.cs |
High entropy of concatenated method names: 'VsYjwdcp', 'jAGsauzxlaBtYm', 'uBIfrUJxdEg', 'ROggXEKEH', 'skfRutZuJx', 'ypvVxxTaC', 'nujiiFtdoNhS', 'JYzaaPYjvjES', 'kLZHreEmFpw', 'LofQUjZgLlxyX' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, xeRJPXmwavvZh.cs |
High entropy of concatenated method names: 'VuqpJUTheDe', 'znrPvdHAVP', 'cAyIiGOFzkOT', 'HOUaRQzOf', 'XzFKzRRgBGUNoLM', 'bQxfglThIhJhj', 'PMxBaJdw', 'niDNNpuaJN', 'ojQARmfXCSIjw', 'qIPmkDHfCJxdXGs' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, rZjCSSmKXaUqXO.cs |
High entropy of concatenated method names: 'dlETBnKBmzDv', 'qxyyxYISrIfceYU', 'mEonbfpiuJAgXx', 'OXrTZcVt', 'FJldZrWPqJAuPIT', 'HQDnXcvuE', 'FmEuQQLohR', 'MIDmlqOxJzPYIRM', 'FbdOrYJmkK', 'tjiaaBSvHzAmmhx' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, KaCEkWzArz.cs |
High entropy of concatenated method names: 'TRJrolTMln', 'tonIFMNIZBwi', 'MKXzNLdyFCKiXye', 'BucahgNQbRnniZ', 'XiNfeOUyZ', 'eolcahOiV', 'HTIOfxGXwYq', 'frnzKTAYhv', 'QDsboAkZ', 'NADDayzg' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, vzOQfCjdwrwlD.cs |
High entropy of concatenated method names: 'DZSBOsEdSkftm', 'CHkhhdMlBNYW', 'xQXiDVjowcoBI', 'RgdllPHbpHPD', 'XRYFcrMHNvC', 'XCoFfwgZxuFX', 'mGZVbPTAvMWX', 'LJwYElbJOMT', 'KKieccLBcpl', 'llfibbqRhIkXd' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, wgtJFxwmDCkn.cs |
High entropy of concatenated method names: 'bqEIfXfZOiYonfU', 'nuaTxiBEdpUSV', 'ZXsCuXbSrjW', 'hyVVRScD', 'HJTAtpzfpD', 'DpIBwllwHV', 'rxtACjIY', 'pRIRNYBA', 'bnBgIzrpUYfgf', 'uESWGsmQWRAXmhq' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, WfcSxBiJWHQqTp.cs |
High entropy of concatenated method names: 'PROyGYfLwtjlP', 'HShuatetG', 'uCbiJigZKDT', 'HxqQqUgYOQSyPoi', 'swEWKuEExwBNNJa', 'rILkEKCKM', 'FdjcSVAkgOzxn', 'tlSuSTLEq', 'HGdyrituJ', 'paUVdgNdcLMt' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, LtuDkZEKFIyjL.cs |
High entropy of concatenated method names: 'zIEsmyYznoUPjWT', 'ZPaJmzDKLHfp', 'hMOQgSAS', 'UGOLGFiVphrci', 'IBJAEtgeTivGc', 'yDDSKovU', 'atycqSyybydGPWS', 'YEpnfQzccXmdYRu', 'nGjHGRqMUjTIyy', 'gkXmjFhPKtVzT' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, uBecUVPQ.cs |
High entropy of concatenated method names: '_003CStart_003Eb__1_0', '_003CUninstall_003Eb__2_0', '_003CLoopInstall_003Eb__7_0', '_003CStartAsBypass_003Eb__10_0', 'AaqmPntZxR', 'BYucXNJtAttu', 'fCgVMnQqp', 'jZNmaLjR', 'jSzWGBFGMVP', 'GfeHMHXNKBq' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, rTbUtmWcnO.cs |
High entropy of concatenated method names: 'ETuZUDsFHdsPqem', 'WQoYDPhzWL', 'NHsdoETuthXISt', 'YkyElqHXzL', 'pvomvDJNfyOzEKW', 'thzIVfnqxASaz', 'ktSpPYGH', 'UzFORJkutOGOq', 'DcKHyouk', 'NZOVhOvydlufJ' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, kICtJPxSafoGvi.cs |
High entropy of concatenated method names: 'izoVMEnyZoDuo', 'ZzsriRjjE', 'MObKRbqhKZYMlY', 'mxKcEGVJI', 'gvPMQxzu', 'JxcchyxVkPlMOTi', 'UZGAjqFTJlfbVtb', 'SmPKJUcdGkl', 'WoRcgQwXstPSrJT', 'TWAqnMubEYmzwdu' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, bNrRgbuKfhLKh.cs |
High entropy of concatenated method names: 'dcgBjalp', 'QTRdGVQS', 'MNYAcNFsv', 'ngqakeeDYY', 'XzmIbxPynoOP', 'xUecATvq', 'TBYZthybSsue', 'OmrAPqtHdZRpcP', 'BCEcosfkkBEizMW', 'UWIGslzDFxX' |
Source: xdwdMicrosoft PowerPoint Host.exe.19.dr, KPKTbmek.cs |
High entropy of concatenated method names: 'ywDpYFYr', 'iSYaQgfunkCfdU', 'LGzzzbmHVN', 'sIvgJerM', 'udjzdohzui', 'UcoeSGZrOwK', 'MKoWyGaX', 'RCUiWzWLunNnrk', 'UROCFzyVjZ', 'opRisTKhDaT' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, YeASamleCu.cs |
High entropy of concatenated method names: 'xnIxVRYrPBFYu', 'bdMoOrQxtvgEAC', 'aaKjZcdK', 'koKrGQSFGdzIY', 'oCRzuMRRQWnpbv', 'VNyTdDahZrdday', 'DvBkWgHcjxR', 'XnDRpWQkPBp', 'nNVsIQjrStTsoqZ', 'OkOVMjCtV' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, BepYSwIiYsKTkc.cs |
High entropy of concatenated method names: '_003CScreenShot_003Eb__16_0', 'hgYqlsJf', 'sLrZOuAb', 'kOWJOWvoQlcxdqy', 'DFyYevrypfGFjUe', 'iYAOjYSCuxcYDC', 'VsaLoCDQoW', 'UiPqEvHkOEq', 'PenvdgTTvmQlM', 'JppfHLrLD' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, gEjezvihrA.cs |
High entropy of concatenated method names: 'SNPMxFexzSMQ', 'gDOlHAunu', 'YzPPDudfl', 'vNRfanEABU', 'TnWxvgwZqFpXCrN', 'paCVmbxQTmjLT', 'umZLELsRHOgGvNG', 'PnNGOazzMspGeJ', 'lGuLDxqnBpYTnog', 'kKdWwyNhUmay' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, WkKaRrezv.cs |
High entropy of concatenated method names: 'VsYjwdcp', 'jAGsauzxlaBtYm', 'uBIfrUJxdEg', 'ROggXEKEH', 'skfRutZuJx', 'ypvVxxTaC', 'nujiiFtdoNhS', 'JYzaaPYjvjES', 'kLZHreEmFpw', 'LofQUjZgLlxyX' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, xeRJPXmwavvZh.cs |
High entropy of concatenated method names: 'VuqpJUTheDe', 'znrPvdHAVP', 'cAyIiGOFzkOT', 'HOUaRQzOf', 'XzFKzRRgBGUNoLM', 'bQxfglThIhJhj', 'PMxBaJdw', 'niDNNpuaJN', 'ojQARmfXCSIjw', 'qIPmkDHfCJxdXGs' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, rZjCSSmKXaUqXO.cs |
High entropy of concatenated method names: 'dlETBnKBmzDv', 'qxyyxYISrIfceYU', 'mEonbfpiuJAgXx', 'OXrTZcVt', 'FJldZrWPqJAuPIT', 'HQDnXcvuE', 'FmEuQQLohR', 'MIDmlqOxJzPYIRM', 'FbdOrYJmkK', 'tjiaaBSvHzAmmhx' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, KaCEkWzArz.cs |
High entropy of concatenated method names: 'TRJrolTMln', 'tonIFMNIZBwi', 'MKXzNLdyFCKiXye', 'BucahgNQbRnniZ', 'XiNfeOUyZ', 'eolcahOiV', 'HTIOfxGXwYq', 'frnzKTAYhv', 'QDsboAkZ', 'NADDayzg' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, vzOQfCjdwrwlD.cs |
High entropy of concatenated method names: 'DZSBOsEdSkftm', 'CHkhhdMlBNYW', 'xQXiDVjowcoBI', 'RgdllPHbpHPD', 'XRYFcrMHNvC', 'XCoFfwgZxuFX', 'mGZVbPTAvMWX', 'LJwYElbJOMT', 'KKieccLBcpl', 'llfibbqRhIkXd' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, wgtJFxwmDCkn.cs |
High entropy of concatenated method names: 'bqEIfXfZOiYonfU', 'nuaTxiBEdpUSV', 'ZXsCuXbSrjW', 'hyVVRScD', 'HJTAtpzfpD', 'DpIBwllwHV', 'rxtACjIY', 'pRIRNYBA', 'bnBgIzrpUYfgf', 'uESWGsmQWRAXmhq' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, WfcSxBiJWHQqTp.cs |
High entropy of concatenated method names: 'PROyGYfLwtjlP', 'HShuatetG', 'uCbiJigZKDT', 'HxqQqUgYOQSyPoi', 'swEWKuEExwBNNJa', 'rILkEKCKM', 'FdjcSVAkgOzxn', 'tlSuSTLEq', 'HGdyrituJ', 'paUVdgNdcLMt' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, LtuDkZEKFIyjL.cs |
High entropy of concatenated method names: 'zIEsmyYznoUPjWT', 'ZPaJmzDKLHfp', 'hMOQgSAS', 'UGOLGFiVphrci', 'IBJAEtgeTivGc', 'yDDSKovU', 'atycqSyybydGPWS', 'YEpnfQzccXmdYRu', 'nGjHGRqMUjTIyy', 'gkXmjFhPKtVzT' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, uBecUVPQ.cs |
High entropy of concatenated method names: '_003CStart_003Eb__1_0', '_003CUninstall_003Eb__2_0', '_003CLoopInstall_003Eb__7_0', '_003CStartAsBypass_003Eb__10_0', 'AaqmPntZxR', 'BYucXNJtAttu', 'fCgVMnQqp', 'jZNmaLjR', 'jSzWGBFGMVP', 'GfeHMHXNKBq' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, rTbUtmWcnO.cs |
High entropy of concatenated method names: 'ETuZUDsFHdsPqem', 'WQoYDPhzWL', 'NHsdoETuthXISt', 'YkyElqHXzL', 'pvomvDJNfyOzEKW', 'thzIVfnqxASaz', 'ktSpPYGH', 'UzFORJkutOGOq', 'DcKHyouk', 'NZOVhOvydlufJ' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, kICtJPxSafoGvi.cs |
High entropy of concatenated method names: 'izoVMEnyZoDuo', 'ZzsriRjjE', 'MObKRbqhKZYMlY', 'mxKcEGVJI', 'gvPMQxzu', 'JxcchyxVkPlMOTi', 'UZGAjqFTJlfbVtb', 'SmPKJUcdGkl', 'WoRcgQwXstPSrJT', 'TWAqnMubEYmzwdu' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, bNrRgbuKfhLKh.cs |
High entropy of concatenated method names: 'dcgBjalp', 'QTRdGVQS', 'MNYAcNFsv', 'ngqakeeDYY', 'XzmIbxPynoOP', 'xUecATvq', 'TBYZthybSsue', 'OmrAPqtHdZRpcP', 'BCEcosfkkBEizMW', 'UWIGslzDFxX' |
Source: 19.2.pto2q1ow.nf5.exe.12f8ceb0.0.raw.unpack, KPKTbmek.cs |
High entropy of concatenated method names: 'ywDpYFYr', 'iSYaQgfunkCfdU', 'LGzzzbmHVN', 'sIvgJerM', 'udjzdohzui', 'UcoeSGZrOwK', 'MKoWyGaX', 'RCUiWzWLunNnrk', 'UROCFzyVjZ', 'opRisTKhDaT' |
Source: xdwdPutty.exe.33.dr, YeASamleCu.cs |
High entropy of concatenated method names: 'xnIxVRYrPBFYu', 'bdMoOrQxtvgEAC', 'aaKjZcdK', 'koKrGQSFGdzIY', 'oCRzuMRRQWnpbv', 'VNyTdDahZrdday', 'DvBkWgHcjxR', 'XnDRpWQkPBp', 'nNVsIQjrStTsoqZ', 'OkOVMjCtV' |
Source: xdwdPutty.exe.33.dr, BepYSwIiYsKTkc.cs |
High entropy of concatenated method names: '_003CScreenShot_003Eb__16_0', 'hgYqlsJf', 'sLrZOuAb', 'kOWJOWvoQlcxdqy', 'DFyYevrypfGFjUe', 'iYAOjYSCuxcYDC', 'VsaLoCDQoW', 'UiPqEvHkOEq', 'PenvdgTTvmQlM', 'JppfHLrLD' |
Source: xdwdPutty.exe.33.dr, gEjezvihrA.cs |
High entropy of concatenated method names: 'SNPMxFexzSMQ', 'gDOlHAunu', 'YzPPDudfl', 'vNRfanEABU', 'TnWxvgwZqFpXCrN', 'paCVmbxQTmjLT', 'umZLELsRHOgGvNG', 'PnNGOazzMspGeJ', 'lGuLDxqnBpYTnog', 'kKdWwyNhUmay' |
Source: xdwdPutty.exe.33.dr, WkKaRrezv.cs |
High entropy of concatenated method names: 'VsYjwdcp', 'jAGsauzxlaBtYm', 'uBIfrUJxdEg', 'ROggXEKEH', 'skfRutZuJx', 'ypvVxxTaC', 'nujiiFtdoNhS', 'JYzaaPYjvjES', 'kLZHreEmFpw', 'LofQUjZgLlxyX' |
Source: xdwdPutty.exe.33.dr, xeRJPXmwavvZh.cs |
High entropy of concatenated method names: 'VuqpJUTheDe', 'znrPvdHAVP', 'cAyIiGOFzkOT', 'HOUaRQzOf', 'XzFKzRRgBGUNoLM', 'bQxfglThIhJhj', 'PMxBaJdw', 'niDNNpuaJN', 'ojQARmfXCSIjw', 'qIPmkDHfCJxdXGs' |
Source: xdwdPutty.exe.33.dr, rZjCSSmKXaUqXO.cs |
High entropy of concatenated method names: 'dlETBnKBmzDv', 'qxyyxYISrIfceYU', 'mEonbfpiuJAgXx', 'OXrTZcVt', 'FJldZrWPqJAuPIT', 'HQDnXcvuE', 'FmEuQQLohR', 'MIDmlqOxJzPYIRM', 'FbdOrYJmkK', 'tjiaaBSvHzAmmhx' |
Source: xdwdPutty.exe.33.dr, KaCEkWzArz.cs |
High entropy of concatenated method names: 'TRJrolTMln', 'tonIFMNIZBwi', 'MKXzNLdyFCKiXye', 'BucahgNQbRnniZ', 'XiNfeOUyZ', 'eolcahOiV', 'HTIOfxGXwYq', 'frnzKTAYhv', 'QDsboAkZ', 'NADDayzg' |
Source: xdwdPutty.exe.33.dr, vzOQfCjdwrwlD.cs |
High entropy of concatenated method names: 'DZSBOsEdSkftm', 'CHkhhdMlBNYW', 'xQXiDVjowcoBI', 'RgdllPHbpHPD', 'XRYFcrMHNvC', 'XCoFfwgZxuFX', 'mGZVbPTAvMWX', 'LJwYElbJOMT', 'KKieccLBcpl', 'llfibbqRhIkXd' |
Source: xdwdPutty.exe.33.dr, wgtJFxwmDCkn.cs |
High entropy of concatenated method names: 'bqEIfXfZOiYonfU', 'nuaTxiBEdpUSV', 'ZXsCuXbSrjW', 'hyVVRScD', 'HJTAtpzfpD', 'DpIBwllwHV', 'rxtACjIY', 'pRIRNYBA', 'bnBgIzrpUYfgf', 'uESWGsmQWRAXmhq' |
Source: xdwdPutty.exe.33.dr, WfcSxBiJWHQqTp.cs |
High entropy of concatenated method names: 'PROyGYfLwtjlP', 'HShuatetG', 'uCbiJigZKDT', 'HxqQqUgYOQSyPoi', 'swEWKuEExwBNNJa', 'rILkEKCKM', 'FdjcSVAkgOzxn', 'tlSuSTLEq', 'HGdyrituJ', 'paUVdgNdcLMt' |
Source: xdwdPutty.exe.33.dr, LtuDkZEKFIyjL.cs |
High entropy of concatenated method names: 'zIEsmyYznoUPjWT', 'ZPaJmzDKLHfp', 'hMOQgSAS', 'UGOLGFiVphrci', 'IBJAEtgeTivGc', 'yDDSKovU', 'atycqSyybydGPWS', 'YEpnfQzccXmdYRu', 'nGjHGRqMUjTIyy', 'gkXmjFhPKtVzT' |
Source: xdwdPutty.exe.33.dr, uBecUVPQ.cs |
High entropy of concatenated method names: '_003CStart_003Eb__1_0', '_003CUninstall_003Eb__2_0', '_003CLoopInstall_003Eb__7_0', '_003CStartAsBypass_003Eb__10_0', 'AaqmPntZxR', 'BYucXNJtAttu', 'fCgVMnQqp', 'jZNmaLjR', 'jSzWGBFGMVP', 'GfeHMHXNKBq' |
Source: xdwdPutty.exe.33.dr, rTbUtmWcnO.cs |
High entropy of concatenated method names: 'ETuZUDsFHdsPqem', 'WQoYDPhzWL', 'NHsdoETuthXISt', 'YkyElqHXzL', 'pvomvDJNfyOzEKW', 'thzIVfnqxASaz', 'ktSpPYGH', 'UzFORJkutOGOq', 'DcKHyouk', 'NZOVhOvydlufJ' |
Source: xdwdPutty.exe.33.dr, kICtJPxSafoGvi.cs |
High entropy of concatenated method names: 'izoVMEnyZoDuo', 'ZzsriRjjE', 'MObKRbqhKZYMlY', 'mxKcEGVJI', 'gvPMQxzu', 'JxcchyxVkPlMOTi', 'UZGAjqFTJlfbVtb', 'SmPKJUcdGkl', 'WoRcgQwXstPSrJT', 'TWAqnMubEYmzwdu' |
Source: xdwdPutty.exe.33.dr, bNrRgbuKfhLKh.cs |
High entropy of concatenated method names: 'dcgBjalp', 'QTRdGVQS', 'MNYAcNFsv', 'ngqakeeDYY', 'XzmIbxPynoOP', 'xUecATvq', 'TBYZthybSsue', 'OmrAPqtHdZRpcP', 'BCEcosfkkBEizMW', 'UWIGslzDFxX' |
Source: xdwdPutty.exe.33.dr, KPKTbmek.cs |
High entropy of concatenated method names: 'ywDpYFYr', 'iSYaQgfunkCfdU', 'LGzzzbmHVN', 'sIvgJerM', 'udjzdohzui', 'UcoeSGZrOwK', 'MKoWyGaX', 'RCUiWzWLunNnrk', 'UROCFzyVjZ', 'opRisTKhDaT' |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\xdwdPutty.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Avast Antivirus" /tr "C:\Users\user\xdwdPutty.exe" & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo 5 /tn "Google Drive" /tr "C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c start /b powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe"' & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c start /b powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe"' & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\ptKNiAaGus.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Avast Antivirus" /tr "C:\Users\user\xdwdPutty.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo 5 /tn "Google Drive" /tr "C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe" /RL HIGHEST |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe"' |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Users\user\xdwdPutty.exe "C:\Users\user\xdwdPutty.exe" |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "OpenOffice" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" & exit |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Azure DevOps" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" /RL HIGHEST & exit |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo 5 /tn "Corel PaintShop Pro" /tr "C:\Users\user\Videos\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\pto2q1ow.nf5.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "OpenOffice" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell ExecutionPolicy Bypass Start-Process -FilePath '"C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe"' |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe" |
|
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\z4wwumki.3zg.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Azure DevOps" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\xdwdPutty.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Azure DevOps" /tr "C:\Users\user\Videos\xdwdMicrosoft PowerPoint Host.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\xdwdPutty.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Users\user\AppData\Roaming\xdwdMicrosoft Paint.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Avast Antivirus" |
|
Source: C:\Users\user\xdwdPutty.exe |
Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST & exit |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "Microsoft Word" /tr "C:\Users\user\xdwdPutty.exe" /RL HIGHEST |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|