Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_00416078 | 12_2_00416078 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_003ED060 | 12_2_003ED060 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_0041B336 | 12_2_0041B336 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_00424609 | 12_2_00424609 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_0040F700 | 12_2_0040F700 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_00409730 | 12_2_00409730 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_004118EF | 12_2_004118EF |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_004138A0 | 12_2_004138A0 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_0041E919 | 12_2_0041E919 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_0040FA8E | 12_2_0040FA8E |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_0041DB30 | 12_2_0041DB30 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_00422EC5 | 12_2_00422EC5 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_003F0E90 | 12_2_003F0E90 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00DA6078 | 13_2_00DA6078 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00D7D060 | 13_2_00D7D060 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00DAB336 | 13_2_00DAB336 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00DB4609 | 13_2_00DB4609 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00D9F700 | 13_2_00D9F700 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00D99730 | 13_2_00D99730 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00DA18EF | 13_2_00DA18EF |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00DA38A0 | 13_2_00DA38A0 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00DAE919 | 13_2_00DAE919 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00D9FA8E | 13_2_00D9FA8E |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00DADB30 | 13_2_00DADB30 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00DB2EC5 | 13_2_00DB2EC5 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00D80E90 | 13_2_00D80E90 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_009ACA2C | 14_2_009ACA2C |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_009ACB70 | 14_2_009ACB70 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_0092FD40 | 14_2_0092FD40 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BA6710 | 14_2_00BA6710 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00ADA2CD | 14_2_00ADA2CD |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BB7410 | 14_2_00BB7410 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00B146B0 | 14_2_00B146B0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00AED9E0 | 14_2_00AED9E0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00AD2AA0 | 14_2_00AD2AA0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00AD5A34 | 14_2_00AD5A34 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00B99F6C | 14_2_00B99F6C |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00AD9F4D | 14_2_00AD9F4D |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_008FB5B8 | 14_2_008FB5B8 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BE46C4 | 14_2_00BE46C4 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BE5E64 | 14_2_00BE5E64 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00C03B88 | 14_2_00C03B88 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BFEB1C | 14_2_00BFEB1C |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BE86F0 | 14_2_00BE86F0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BE714B | 14_2_00BE714B |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00C8629F | 14_2_00C8629F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00C86C97 | 14_2_00C86C97 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00C86EAC | 14_2_00C86EAC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00CD87ED | 14_2_00CD87ED |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00CC1D5A | 14_2_00CC1D5A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01B4B19D | 14_2_01B4B19D |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01B47D70 | 14_2_01B47D70 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01B480D6 | 14_2_01B480D6 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01B3C303 | 14_2_01B3C303 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01B40B62 | 14_2_01B40B62 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01B49F5A | 14_2_01B49F5A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01B3F223 | 14_2_01B3F223 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01B49E29 | 14_2_01B49E29 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01DF05D7 | 14_2_01DF05D7 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01DEF000 | 14_2_01DEF000 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01DEF720 | 14_2_01DEF720 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01C8773A | 14_2_01C8773A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01C844C4 | 14_2_01C844C4 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_01C85C1F | 14_2_01C85C1F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00ADB5B8 | 26_2_00ADB5B8 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00D86710 | 26_2_00D86710 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00CBA2CD | 26_2_00CBA2CD |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00D97410 | 26_2_00D97410 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00CF46B0 | 26_2_00CF46B0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00CCD9E0 | 26_2_00CCD9E0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00CB2AA0 | 26_2_00CB2AA0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00CB5A34 | 26_2_00CB5A34 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00CB9F4D | 26_2_00CB9F4D |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00D79F6C | 26_2_00D79F6C |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00B0FD40 | 26_2_00B0FD40 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00DC46C4 | 26_2_00DC46C4 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00DC5E64 | 26_2_00DC5E64 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00DC86F0 | 26_2_00DC86F0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00DC714B | 26_2_00DC714B |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00DE3B88 | 26_2_00DE3B88 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00DDEB1C | 26_2_00DDEB1C |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00EB87ED | 26_2_00EB87ED |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00EA1D5A | 26_2_00EA1D5A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00E66EAC | 26_2_00E66EAC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00E66C97 | 26_2_00E66C97 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_00E6629F | 26_2_00E6629F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F5E5B7 | 26_2_01F5E5B7 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_020ED669 | 26_2_020ED669 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_02012686 | 26_2_02012686 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F5CD4B | 26_2_01F5CD4B |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F5D938 | 26_2_01F5D938 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F608E9 | 26_2_01F608E9 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F5BCBE | 26_2_01F5BCBE |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F5CFB0 | 26_2_01F5CFB0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F613B3 | 26_2_01F613B3 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F5A77A | 26_2_01F5A77A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F60B6A | 26_2_01F60B6A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_0200C8D7 | 26_2_0200C8D7 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_01F5DF1F | 26_2_01F5DF1F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 26_2_02042933 | 26_2_02042933 |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\hBqTrQLya4.msi" | |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 6BAD67B4EB347E35097C3D98448E2079 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\Installer\MSIDD62.tmp "C:\Windows\Installer\MSIDD62.tmp" /DontWait /HideWindow "C:\Users\user\Documents\Windows10.cmd" C:\Users\user\Documents\ | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\Installer\MSIDD92.tmp "C:\Windows\Installer\MSIDD92.tmp" /DontWait /HideWindow "C:\Users\user\Pictures\fotosdaviagem\cont.cmd" C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\ | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Documents\Windows10.cmd" C:\Users\user\Documents\" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Pictures\fotosdaviagem\cont.cmd" C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc create MeuServico binPath= "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" start= auto | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc start MeuServico | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://45.90.123.184/clientes/inspecionando.php | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2280 --field-trial-handle=2224,i,3053730682193171380,1241186122492042118,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" /systemstartup | |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" -type:exit-monitor-method:collectupload-session-token | |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" --type=utility--utility-sub-type=network.mojom. | |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" --type=gpu-process--field-trial-handle=4305.474 | |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" --type=renderer--field-trial-handle=4304.754958 | |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" neto2 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 6BAD67B4EB347E35097C3D98448E2079 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\Installer\MSIDD62.tmp "C:\Windows\Installer\MSIDD62.tmp" /DontWait /HideWindow "C:\Users\user\Documents\Windows10.cmd" C:\Users\user\Documents\ | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Windows\Installer\MSIDD92.tmp "C:\Windows\Installer\MSIDD92.tmp" /DontWait /HideWindow "C:\Users\user\Pictures\fotosdaviagem\cont.cmd" C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\ | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" /systemstartup | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" -type:exit-monitor-method:collectupload-session-token | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" --type=utility--utility-sub-type=network.mojom. | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" --type=gpu-process--field-trial-handle=4305.474 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" --type=renderer--field-trial-handle=4304.754958 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc create MeuServico binPath= "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" start= auto | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc start MeuServico | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://45.90.123.184/clientes/inspecionando.php | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2280 --field-trial-handle=2224,i,3053730682193171380,1241186122492042118,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process created: C:\Users\user\Pictures\fotosdaviagem\windows10.exe "C:\Users\user\Pictures\fotosdaviagem\windows10.exe" neto2 | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windows.ui.immersive.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD62.tmp | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD62.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD62.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD62.tmp | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD62.tmp | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD62.tmp | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD92.tmp | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD92.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD92.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD92.tmp | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD92.tmp | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD92.tmp | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: starburn.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: windows.shell.servicehostbuilder.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: ieframe.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: starburn.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: starburn.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: starburn.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: starburn.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: starburn.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: starburn.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: magnification.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: d3d9.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: slwga.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: schedcli.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: security.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: wevtapi.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: olepro32.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: activeds.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: adsldpc.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: dxva2.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: idndl.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: 12_2_004081F0 push ecx; ret | 12_2_00408203 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: 13_2_00D981F0 push ecx; ret | 13_2_00D98203 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BCB794 push 00BCB82Ah; ret | 14_2_00BCB822 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BCA3C8 push 00BCA465h; ret | 14_2_00BCA45D |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BCADB8 push 00BCAE20h; ret | 14_2_00BCAE18 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BCA69C push 00BCA738h; ret | 14_2_00BCA730 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BCA48C push 00BCA542h; ret | 14_2_00BCA53A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BCB028 push 00BCB222h; ret | 14_2_00BCB21A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BCA570 push 00BCA5BAh; ret | 14_2_00BCA5B2 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BCA569 push 00BCA5BAh; ret | 14_2_00BCA5B2 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00BCB244 push 00BCB2E3h; ret | 14_2_00BCB2DB |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00964084 push ecx; mov dword ptr [esp], edx | 14_2_00964085 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00932050 push ecx; mov dword ptr [esp], eax | 14_2_00932051 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_0095C078 push ecx; mov dword ptr [esp], ecx | 14_2_0095C07C |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_009211A0 push ecx; mov dword ptr [esp], eax | 14_2_009211A1 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_009611F8 push ecx; mov dword ptr [esp], ecx | 14_2_009611FC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_009A6138 push ecx; mov dword ptr [esp], edx | 14_2_009A613A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00919120 push 009191B9h; ret | 14_2_009191B1 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00960154 push ecx; mov dword ptr [esp], edx | 14_2_00960155 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_0095F144 push ecx; mov dword ptr [esp], ecx | 14_2_0095F148 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00921170 push ecx; mov dword ptr [esp], eax | 14_2_00921171 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00960164 push ecx; mov dword ptr [esp], edx | 14_2_00960165 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_0095D160 push ecx; mov dword ptr [esp], ecx | 14_2_0095D164 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_0095A2D8 push ecx; mov dword ptr [esp], ecx | 14_2_0095A2DC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_00959250 push ecx; mov dword ptr [esp], edx | 14_2_00959251 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_0095E3AC push ecx; mov dword ptr [esp], ecx | 14_2_0095E3B0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_0095D34C push ecx; mov dword ptr [esp], ecx | 14_2_0095D350 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_009634A4 push ecx; mov dword ptr [esp], edx | 14_2_009634A5 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_009624A8 push ecx; mov dword ptr [esp], edx | 14_2_009624A9 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_0095A4C4 push ecx; mov dword ptr [esp], ecx | 14_2_0095A4C8 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Code function: 14_2_009995DC push ecx; mov dword ptr [esp], edx | 14_2_009995E1 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 6E0005 value: E9 8B 2F 08 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 77762F90 value: E9 7A D0 F7 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 3750005 value: E9 2B BA FD 73 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 7772BA30 value: E9 DA 45 02 8C | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 3760008 value: E9 8B 8E 01 74 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 77778E90 value: E9 80 71 FE 8B | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 3990005 value: E9 8B 4D 0A 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 75A34D90 value: E9 7A B2 F5 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 39B0005 value: E9 EB EB 09 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 75A4EBF0 value: E9 1A 14 F6 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 39C0005 value: E9 8B 8A C1 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 765D8A90 value: E9 7A 75 3E 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 39D0005 value: E9 2B 02 C3 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 7416 base: 76600230 value: E9 DA FD 3C 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 720005 value: E9 8B 2F 04 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 77762F90 value: E9 7A D0 FB 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 740005 value: E9 2B BA FE 76 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 7772BA30 value: E9 DA 45 01 89 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 750008 value: E9 8B 8E 02 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 77778E90 value: E9 80 71 FD 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 770005 value: E9 8B 4D 2C 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 75A34D90 value: E9 7A B2 D3 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 780005 value: E9 EB EB 2C 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 75A4EBF0 value: E9 1A 14 D3 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 790005 value: E9 8B 8A E4 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 765D8A90 value: E9 7A 75 1B 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 7A0005 value: E9 2B 02 E6 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8260 base: 76600230 value: E9 DA FD 19 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 700005 value: E9 8B 2F 06 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 77762F90 value: E9 7A D0 F9 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 720005 value: E9 2B BA 00 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 7772BA30 value: E9 DA 45 FF 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 740008 value: E9 8B 8E 03 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 77778E90 value: E9 80 71 FC 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 3890005 value: E9 8B 4D 1A 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 75A34D90 value: E9 7A B2 E5 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 38A0005 value: E9 EB EB 1A 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 75A4EBF0 value: E9 1A 14 E5 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 38B0005 value: E9 8B 8A D2 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 765D8A90 value: E9 7A 75 2D 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 38C0005 value: E9 2B 02 D4 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8272 base: 76600230 value: E9 DA FD 2B 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 6E0005 value: E9 8B 2F 08 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 77762F90 value: E9 7A D0 F7 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 750005 value: E9 2B BA FD 76 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 7772BA30 value: E9 DA 45 02 89 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 760008 value: E9 8B 8E 01 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 77778E90 value: E9 80 71 FE 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 780005 value: E9 8B 4D 2B 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 75A34D90 value: E9 7A B2 D4 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 790005 value: E9 EB EB 2B 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 75A4EBF0 value: E9 1A 14 D4 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 39B0005 value: E9 8B 8A C2 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 765D8A90 value: E9 7A 75 3D 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 39C0005 value: E9 2B 02 C4 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8288 base: 76600230 value: E9 DA FD 3B 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 610005 value: E9 8B 2F 15 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 77762F90 value: E9 7A D0 EA 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 3960005 value: E9 2B BA DC 73 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 7772BA30 value: E9 DA 45 23 8C | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 3970008 value: E9 8B 8E E0 73 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 77778E90 value: E9 80 71 1F 8C | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 3990005 value: E9 8B 4D 0A 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 75A34D90 value: E9 7A B2 F5 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 39A0005 value: E9 EB EB 0A 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 75A4EBF0 value: E9 1A 14 F5 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 39C0005 value: E9 8B 8A C1 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 765D8A90 value: E9 7A 75 3E 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 39D0005 value: E9 2B 02 C3 72 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8304 base: 76600230 value: E9 DA FD 3C 8D | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 6D0005 value: E9 8B 2F 09 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 77762F90 value: E9 7A D0 F6 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 6F0005 value: E9 2B BA 03 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 7772BA30 value: E9 DA 45 FC 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 860008 value: E9 8B 8E F1 76 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 77778E90 value: E9 80 71 0E 89 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 880005 value: E9 8B 4D 1B 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 75A34D90 value: E9 7A B2 E4 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 890005 value: E9 EB EB 1B 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 75A4EBF0 value: E9 1A 14 E4 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 8A0005 value: E9 8B 8A D3 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 765D8A90 value: E9 7A 75 2C 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 8B0005 value: E9 2B 02 D5 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8312 base: 76600230 value: E9 DA FD 2A 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 6D0005 value: E9 8B 2F 09 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 77762F90 value: E9 7A D0 F6 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 730005 value: E9 2B BA FF 76 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 7772BA30 value: E9 DA 45 00 89 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 740008 value: E9 8B 8E 03 77 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 77778E90 value: E9 80 71 FC 88 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 870005 value: E9 8B 4D 1C 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 75A34D90 value: E9 7A B2 E3 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 880005 value: E9 EB EB 1C 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 75A4EBF0 value: E9 1A 14 E3 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 890005 value: E9 8B 8A D4 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 765D8A90 value: E9 7A 75 2B 8A | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 8A0005 value: E9 2B 02 D6 75 | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Memory written: PID: 8524 base: 76600230 value: E9 DA FD 29 8A | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1CA6817 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 13C3FE1 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DCD28A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D5CC61 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1EBB7DD |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D9F9F2 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1EC362F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D4FE3A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 13E88A0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DE4F13 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1C6EB9A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D86EF5 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DEF32F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F178CC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D3DC69 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F7C9C0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E4EB9A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1B9DC69 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1403FE1 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1CAEB9A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E46F41 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F7C237 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E7D28A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1EE8C0A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DFC9C0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 13EB8A4 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1CA2E43 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1C9E90D |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D3AF83 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E4837E |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F2FE3A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1EB0774 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 20F78CC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F902EA |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1B9AF83 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1B25C50 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1EFB7DD |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DF02EA |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E0D28A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D10774 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 13CB8A4 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1C5DC69 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D55D9C |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 14B89BC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1BFA8D4 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1B95C50 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E4F9F2 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D80774 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E9F32F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E602EA |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1BAA8D4 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1B1E90D |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DBCC61 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D836DB |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E4F32F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E2D28A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F2362F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1BE5C50 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E0AEF7 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D6837E |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E4FE3A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D6EB9A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E236DB |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DD0774 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 20178CC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 15C88A0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F036DB |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1FC4F13 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F66EF5 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 14689BC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DFFE3A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DD36DB |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D1EB9A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E2F32F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D8FE3A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F578CC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1D636DB |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1FA40E0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DE6EF5 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F778CC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E44F13 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 20440E0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1EB02EA |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1EE4F13 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F1238B |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 205B321 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 20940E0 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1521870 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1C0E90D |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 201362F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F3F32F |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DB837E |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 15089BC |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E9FE3A |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 14DB8A4 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1E736DB |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1F34F13 |
Source: C:\Users\user\Pictures\fotosdaviagem\windows10.exe | API/Special instruction interceptor: Address: 1DBEB9A |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: Datacenter without Hyper-V Core |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004D48000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: #Microsoft-Windows-Hyper-V-VID-Admin |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004C7B000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: 0Microsoft-Windows-Hyper-V-Guest-Drivers/Diagnoseal |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009DA000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/Analytic |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009DA000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Hypervisor-Operational |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/AdminLMEM` |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-VID-AnalyticLMEMP |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: QEMUU |
Source: windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: VMWARE |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Hypervisor-OperationalLMEMh |
Source: windows10.exe, 00000020.00000003.1622504533.000000007FDC0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: SecureVirtualMachine |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004CCD000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: -Microsoft-Windows-Hyper-V-Hypervisor-Analytic |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004C7B000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: 3Microsoft-Windows-Hyper-V-Guest-Drivers/Operational |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004D3A000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: *Microsoft-Windows-Hyper-V-Hypervisor-Admin` |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/DiagnoseLMEMh |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Hypervisor-AdminLMEMX |
Source: windows10.exe, 00000020.00000003.1622504533.000000007FDC0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: fsSecureVirtualMachine |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009E3000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1649607522.00000000009E3000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/Admin |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004C7B000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: 0Microsoft-Windows-Hyper-V-Hypervisor-Operational |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/AnalyticLMEMh |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009DA000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-VID-Admin |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: Datacenter without Hyper-V Full |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: Enterprise without Hyper-V Full |
Source: windows10.exe, 00000020.00000003.1649481472.00000000009CB000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1650085239.00000000009CF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-NETVSC/Diagnostic |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004CCD000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: -Microsoft-Windows-Hyper-V-Guest-Drivers/Admin |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: Microsoft Hyper-V Server |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009E3000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1649607522.00000000009E3000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/Debug |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: Standard without Hyper-V Full |
Source: windows10.exe, 00000020.00000003.1648660506.00000000009AF000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648687824.00000000009AD000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-NETVSC/DiagnosticLMEMX |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: Enterprise without Hyper-V Core |
Source: windows10.exe, 00000020.00000002.2500690290.00000000009B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dlli |
Source: windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: stVMWare |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009DA000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648631286.00000000009DD000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648687824.00000000009DD000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1649150067.00000000009DD000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-VID-AnalyticRJU"+ |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: stQEMU |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009E3000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1649607522.00000000009E3000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Hypervisor-Analytic |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009DA000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/Diagnose |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: 6without Hyper-V for Windows Essential Server Solutions |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004D3A000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: +Microsoft-Windows-Hyper-V-NETVSC/Diagnostic` |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004D24000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: &Microsoft-Windows-Hyper-V-VID-Analytic |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/OperationalLMEMh |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Hypervisor-AnalyticLMEM` |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/DebugLMEM` |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004C7B000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: 0Microsoft-Windows-Hyper-V-Guest-Drivers/Analytic |
Source: windows10.exe, 00000020.00000002.2679332883.0000000004CCD000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: -Microsoft-Windows-Hyper-V-Guest-Drivers/Debug |
Source: windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: VMWare |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009DA000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Guest-Drivers/Operational |
Source: windows10.exe, 00000020.00000003.1622019897.000000007FCF0000.00000004.00001000.00020000.00000000.sdmp, windows10.exe, 00000020.00000002.2659394970.0000000003E40000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: Standard without Hyper-V Core |
Source: hBqTrQLya4.msi | Binary or memory string: MvmCiy |
Source: windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-VID-AdminLMEMH |
Source: windows10.exe, 00000020.00000003.1649347613.00000000009E3000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1649607522.00000000009E3000.00000004.00000020.00020000.00000000.sdmp, windows10.exe, 00000020.00000003.1648221309.00000000009A1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft-Windows-Hyper-V-Hypervisor-Admin8" |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: GetLocaleInfoEx,FormatMessageA, | 12_2_003F2161 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: GetLocaleInfoEx, | 12_2_004071C1 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: GetACP,IsValidCodePage,GetLocaleInfoW, | 12_2_00423414 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: EnumSystemLocalesW, | 12_2_004236B6 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: EnumSystemLocalesW, | 12_2_00423701 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: EnumSystemLocalesW, | 12_2_0042379C |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: EnumSystemLocalesW, | 12_2_0041C7A2 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, | 12_2_00423827 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: GetLocaleInfoW, | 12_2_00423A7A |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 12_2_00423BA3 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: GetLocaleInfoW, | 12_2_00423CA9 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 12_2_00423D78 |
Source: C:\Windows\Installer\MSIDD62.tmp | Code function: GetLocaleInfoW, | 12_2_0041CD1F |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: GetLocaleInfoEx, | 13_2_00D971C1 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: GetLocaleInfoEx,FormatMessageA, | 13_2_00D82161 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: GetACP,IsValidCodePage,GetLocaleInfoW, | 13_2_00DB3414 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: EnumSystemLocalesW, | 13_2_00DB36B6 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: EnumSystemLocalesW, | 13_2_00DB379C |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: EnumSystemLocalesW, | 13_2_00DAC7A2 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: EnumSystemLocalesW, | 13_2_00DB3701 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, | 13_2_00DB3827 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: GetLocaleInfoW, | 13_2_00DB3A7A |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 13_2_00DB3BA3 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: GetLocaleInfoW, | 13_2_00DB3CA9 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 13_2_00DB3D78 |
Source: C:\Windows\Installer\MSIDD92.tmp | Code function: GetLocaleInfoW, | 13_2_00DACD1F |