Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\cmd.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\where.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\cmd.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\cmd.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\cmd.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\cmd.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\TamenuV11.msi" | |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1688 --field-trial-handle=1692,i,14834755097693353692,10985245987311762671,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe /A:C "/F:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Setup.lnk" /T:C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --mojo-platform-channel-handle=2248 --field-trial-handle=1692,i,14834755097693353692,10985245987311762671,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1648 --field-trial-handle=1764,i,3145727516655865599,8822023245888026874,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --mojo-platform-channel-handle=2304 --field-trial-handle=1764,i,3145727516655865599,8822023245888026874,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\where.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\msiexec.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1688 --field-trial-handle=1692,i,14834755097693353692,10985245987311762671,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe /A:C "/F:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Setup.lnk" /T:C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --mojo-platform-channel-handle=2248 --field-trial-handle=1692,i,14834755097693353692,10985245987311762671,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1648 --field-trial-handle=1764,i,3145727516655865599,8822023245888026874,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --mojo-platform-channel-handle=2304 --field-trial-handle=1764,i,3145727516655865599,8822023245888026874,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msihnd.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srclient.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: spp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vssapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vsstrace.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ffmpeg.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kbdus.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ffmpeg.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mf.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mfplat.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: rtworkq.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\where.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ffmpeg.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: powrprof.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: umpdc.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kbdus.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: nlaapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ffmpeg.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: powrprof.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: umpdc.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kbdus.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: nlaapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: windows.ui.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: windowmanagementapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: inputhost.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: twinapi.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: twinapi.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mscms.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: coloradapterclient.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wtsapi32.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mmdevapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: devobj.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winsta.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: napinsp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: wshbth.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winrnr.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ffmpeg.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: powrprof.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: umpdc.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dxgi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: resourcepolicyclient.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mf.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mfplat.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: rtworkq.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ffmpeg.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: powrprof.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: umpdc.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kbdus.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: nlaapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\where.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\where.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\where.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\where.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1688 --field-trial-handle=1692,i,14834755097693353692,10985245987311762671,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe /A:C "/F:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Setup.lnk" /T:C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --mojo-platform-channel-handle=2248 --field-trial-handle=1692,i,14834755097693353692,10985245987311762671,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1648 --field-trial-handle=1764,i,3145727516655865599,8822023245888026874,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe "C:\Users\user\AppData\Local\Programs\Setup\Setup.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\Setup" --mojo-platform-channel-handle=2304 --field-trial-handle=1764,i,3145727516655865599,8822023245888026874,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\msiexec.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\Setup\resources VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\package.json VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\windows-shortcuts.js VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\000003.log VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\DVWHKMNFNN.mp3 VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\DVWHKMNFNN.pdf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\HTAGVDFUIE.png VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\JSDNGYCOWY.mp3 VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\KATAXZVCPS.jpg VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\KATAXZVCPS.xlsx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\ONBQCLYSPU.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\VLZDGUKUTZ.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\VLZDGUKUTZ.xlsx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Documents\HTAGVDFUIE.png VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Documents\KATAXZVCPS.jpg VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Documents\VLZDGUKUTZ VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Desktop VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Desktop\JSDNGYCOWY.mp3 VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Applications VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Local State VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79 VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Browser Extensions VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Cookies\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Browser Extensions VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Cookies\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Cookies\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Cookies VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Discord Tokens VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Passwords\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Passwords\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Passwords VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Wallets VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Browser Extensions VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Cookies VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Discord Tokens VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Important Files VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Wallets VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Cookies VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Passwords VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Wallets VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Important Files VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Passwords\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Passwords\Microsoft_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Passwords\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Passwords\Microsoft_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Cookies\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79\Cookies\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79 VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\6a0ac49d-0480-6e43-9966-d7aa27ab7e79 VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Programs VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\Setup VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Roaming\Setup\Local State VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\package.json VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\Setup\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\windows-shortcuts.js VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\000003.log VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\DVWHKMNFNN.mp3 VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\DVWHKMNFNN.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\HTAGVDFUIE.png VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\JSDNGYCOWY.mp3 VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\KATAXZVCPS.jpg VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\KATAXZVCPS.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\VLZDGUKUTZ.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Downloads\YPSIACHYXW.png VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Documents VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Pictures VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Documents\NIKHQAIQAU VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Documents\NWTVCDUMOB VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Documents\RAYHIWGKDI VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Documents\VLZDGUKUTZ.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Documents\VLZDGUKUTZ.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Desktop\KATAXZVCPS.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Desktop\LTKMYBSEYZ VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\Desktop\UMMBDNEQBN.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Applications VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Applications VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Local State VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1 VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Browser Extensions VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Cookies\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Browser Extensions VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Cookies\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Cookies VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Passwords\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Browser Extensions VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Cookies VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Discord Tokens VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Wallets VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Cookies VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Important Files VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Cookies\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Cookies\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Passwords\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\c9ecc06d-d01f-7f76-d9f8-ef3ca6db0df1\Passwords\Microsoft_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\Setup\Setup.exe | Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation | |