Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then shr ecx, 0Dh | 3_2_6CB79DA0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then shr ebp, 0Dh | 3_2_6CB78A50 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then mov dword ptr [esp], edx | 3_2_6CB6CB60 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then mov ebp, edi | 3_2_6CB53000 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then shr ecx, 0Dh | 13_2_6CE09DA0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then shr ebp, 0Dh | 13_2_6CE08A50 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then mov dword ptr [esp], edx | 13_2_6CDFCB60 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then mov ebp, edi | 13_2_6CDE3000 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then shr ecx, 0Dh | 17_2_6CE09DA0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then shr ebp, 0Dh | 17_2_6CE08A50 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then mov dword ptr [esp], edx | 17_2_6CDFCB60 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4x nop then mov ebp, edi | 17_2_6CDE3000 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB67DD0 | 3_2_6CB67DD0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB7AD00 | 3_2_6CB7AD00 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB78E10 | 3_2_6CB78E10 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB8CE40 | 3_2_6CB8CE40 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB5BE4F | 3_2_6CB5BE4F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBA7FB0 | 3_2_6CBA7FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBC6FB0 | 3_2_6CBC6FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB60830 | 3_2_6CB60830 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB65820 | 3_2_6CB65820 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBC2940 | 3_2_6CBC2940 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB7BAB0 | 3_2_6CB7BAB0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBD1A00 | 3_2_6CBD1A00 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB7CA70 | 3_2_6CB7CA70 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB5CA60 | 3_2_6CB5CA60 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBC7490 | 3_2_6CBC7490 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB7C460 | 3_2_6CB7C460 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBC5590 | 3_2_6CBC5590 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB7D525 | 3_2_6CB7D525 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB7B540 | 3_2_6CB7B540 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB53620 | 3_2_6CB53620 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBD1640 | 3_2_6CBD1640 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB7A790 | 3_2_6CB7A790 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBAF732 | 3_2_6CBAF732 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB96730 | 3_2_6CB96730 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBD3710 | 3_2_6CBD3710 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB73090 | 3_2_6CB73090 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB710D0 | 3_2_6CB710D0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB53000 | 3_2_6CB53000 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB8E040 | 3_2_6CB8E040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB86040 | 3_2_6CB86040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB761A0 | 3_2_6CB761A0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB7C100 | 3_2_6CB7C100 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBC5100 | 3_2_6CBC5100 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CB592E0 | 3_2_6CB592E0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBC6240 | 3_2_6CBC6240 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CDF7DD0 | 13_2_6CDF7DD0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE0AD00 | 13_2_6CE0AD00 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CDEBE4F | 13_2_6CDEBE4F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE1CE40 | 13_2_6CE1CE40 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE08E10 | 13_2_6CE08E10 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE37FB0 | 13_2_6CE37FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE56FB0 | 13_2_6CE56FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CDF0830 | 13_2_6CDF0830 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CDF5820 | 13_2_6CDF5820 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE52940 | 13_2_6CE52940 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE0BAB0 | 13_2_6CE0BAB0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE0CA70 | 13_2_6CE0CA70 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CDECA60 | 13_2_6CDECA60 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE61A00 | 13_2_6CE61A00 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE57490 | 13_2_6CE57490 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE0C460 | 13_2_6CE0C460 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE55590 | 13_2_6CE55590 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE0B540 | 13_2_6CE0B540 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE0D525 | 13_2_6CE0D525 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE61640 | 13_2_6CE61640 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CDE3620 | 13_2_6CDE3620 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE0A790 | 13_2_6CE0A790 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE3F732 | 13_2_6CE3F732 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE26730 | 13_2_6CE26730 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE63710 | 13_2_6CE63710 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE010D0 | 13_2_6CE010D0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE03090 | 13_2_6CE03090 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE1E040 | 13_2_6CE1E040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE16040 | 13_2_6CE16040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CDE3000 | 13_2_6CDE3000 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE061A0 | 13_2_6CE061A0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE0C100 | 13_2_6CE0C100 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE55100 | 13_2_6CE55100 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CDE92E0 | 13_2_6CDE92E0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE56240 | 13_2_6CE56240 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CDF7DD0 | 17_2_6CDF7DD0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE0AD00 | 17_2_6CE0AD00 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CDEBE4F | 17_2_6CDEBE4F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE1CE40 | 17_2_6CE1CE40 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE08E10 | 17_2_6CE08E10 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE37FB0 | 17_2_6CE37FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE56FB0 | 17_2_6CE56FB0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CDF0830 | 17_2_6CDF0830 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CDF5820 | 17_2_6CDF5820 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE52940 | 17_2_6CE52940 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE0BAB0 | 17_2_6CE0BAB0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE0CA70 | 17_2_6CE0CA70 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CDECA60 | 17_2_6CDECA60 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE61A00 | 17_2_6CE61A00 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE57490 | 17_2_6CE57490 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE0C460 | 17_2_6CE0C460 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE55590 | 17_2_6CE55590 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE0B540 | 17_2_6CE0B540 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE0D525 | 17_2_6CE0D525 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE61640 | 17_2_6CE61640 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CDE3620 | 17_2_6CDE3620 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE0A790 | 17_2_6CE0A790 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE3F732 | 17_2_6CE3F732 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE26730 | 17_2_6CE26730 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE63710 | 17_2_6CE63710 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE010D0 | 17_2_6CE010D0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE03090 | 17_2_6CE03090 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE1E040 | 17_2_6CE1E040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE16040 | 17_2_6CE16040 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CDE3000 | 17_2_6CDE3000 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE061A0 | 17_2_6CE061A0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE0C100 | 17_2_6CE0C100 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE55100 | 17_2_6CE55100 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CDE92E0 | 17_2_6CDE92E0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE56240 | 17_2_6CE56240 |
Source: unknown | Process created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll" | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",#1 | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarCreate | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",#1 | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6564 -s 836 | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 4216 -s 812 | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarDestroy | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarFreeRec | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarCreate | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarDestroy | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarFreeRec | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",_cgo_dummy_export | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 3788 -s 844 | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellSpell | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellInit | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellFree | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SignalInitializeCrashReporting | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",GetInstallDetailsPayload | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarRecognize | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",#1 | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarCreate | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarDestroy | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\LKwQJxGVXf.dll,BarFreeRec | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarCreate | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarDestroy | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarFreeRec | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",_cgo_dummy_export | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellSpell | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellInit | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SpellFree | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",SignalInitializeCrashReporting | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",GetInstallDetailsPayload | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",BarRecognize | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\LKwQJxGVXf.dll",#1 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CC46FBD push cs; ret | 3_2_6CC46FC5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CC459F2 push es; iretd | 3_2_6CC45A0F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CC476AA push ebx; iretd | 3_2_6CC479EB |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0483B9AB push es; iretd | 4_2_0483B9AE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0483AEB4 push ecx; ret | 4_2_0483AED6 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 11_2_04C38FC3 push es; ret | 11_2_04C38FC6 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 11_2_04C38F4F push es; ret | 11_2_04C38F52 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 11_2_04C38F53 push es; ret | 11_2_04C38F4A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 11_2_04C38F3B push es; ret | 11_2_04C38F4A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CED6FBD push cs; ret | 13_2_6CED6FC5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CED59F2 push es; iretd | 13_2_6CED5A0F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CED76AA push ebx; iretd | 13_2_6CED79EB |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 14_2_04C38FC3 push es; ret | 14_2_04C38FC6 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 14_2_04C3B60B push esi; iretd | 14_2_04C3B982 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 14_2_04C38F4F push es; ret | 14_2_04C38F52 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 14_2_04C3A217 push ds; ret | 14_2_04C3A3B0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 14_2_04C3A3B7 push 0004C303h; ret | 14_2_04C3A58A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 14_2_04C38F3B push es; ret | 14_2_04C38F4A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 14_2_04C3A378 push ds; ret | 14_2_04C3A3B0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 15_2_0483A9E2 push edx; ret | 15_2_0483A9E3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 15_2_0483AEA9 push cs; ret | 15_2_0483AEC7 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CED6FBD push cs; ret | 17_2_6CED6FC5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CED59F2 push es; iretd | 17_2_6CED5A0F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CED76AA push ebx; iretd | 17_2_6CED79EB |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 19_2_04C38FC3 push es; ret | 19_2_04C38FC6 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 19_2_04C38FA1 push es; ret | 19_2_04C38FAA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 19_2_04C3A473 push 0004C303h; ret | 19_2_04C3A58A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 22_2_04C38FC3 push es; ret | 22_2_04C38FC6 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 22_2_04C38F4F push es; ret | 22_2_04C38F52 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 22_2_04C3A418 pushad ; iretd | 22_2_04C3A419 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 22_2_04C38F3B push es; ret | 22_2_04C38F4A |
Source: C:\Windows\System32\loaddll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: rundll32.exe, 0000000E.00000002.2229264812.0000000002D6A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllU |
Source: rundll32.exe, 00000013.00000002.2232490236.0000000002ADA000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll6 |
Source: rundll32.exe, 00000018.00000002.2238595309.000000000315A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll/ |
Source: rundll32.exe, 00000015.00000002.2234698661.000000000064A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll( |
Source: loaddll32.exe, 00000000.00000002.2237856869.0000000000666000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000002.2140730643.0000000002B9A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2139546766.000000000080A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000B.00000002.2166605305.0000000002ACA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.2197069812.00000000033BA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000D.00000002.2232731511.00000000033AA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000F.00000002.2230203030.000000000061A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000014.00000002.2233926444.0000000002E0A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000016.00000002.2234749334.0000000002C3A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000017.00000002.2237851825.0000000002E7A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBD4AE0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, | 3_2_6CBD4AE0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_6CBD4ADC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, | 3_2_6CBD4ADC |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE64AE0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, | 13_2_6CE64AE0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 13_2_6CE64ADC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, | 13_2_6CE64ADC |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE64AE0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, | 17_2_6CE64AE0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 17_2_6CE64ADC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, | 17_2_6CE64ADC |