Source: unknown |
Process created: C:\Users\user\Desktop\minecraft.exe "C:\Users\user\Desktop\minecraft.exe" |
|
Source: C:\Users\user\Desktop\minecraft.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5B39.tmp\5B3A.tmp\5B3B.bat C:\Users\user\Desktop\minecraft.exe" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\fsutil.exe fsutil dirty query C: |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /f /im taskmgr.exe |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /f /im regedit.exe |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\hal.dll /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\hal.dll /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winload.exe /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winload.exe /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winresume.exe /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winresume.exe /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winlogon.exe /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winlogon.exe /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\wininit.exe /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\wininit.exe /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\ntoskrnl.exe /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\ntoskrnl.exe /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\regedit.exe /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\regedit.exe /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\taskmgr.exe /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\taskmgr.exe /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\consent.exe /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\consent.exe /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\drivers /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\drivers /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\shutdown.exe /r /d y |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\shutdown.exe /grant everyone:F /t |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /f /im lsass.exe |
|
Source: unknown |
Process created: C:\Windows\System32\wlrmdr.exe -s -1 -f 2 -t Your PC will automatically restart in one minute -m Windows ran into a problem and needs to restart. You should close this message now and save your work. -a 3 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\reg.exe reg delete HKLM /f |
|
Source: C:\Users\user\Desktop\minecraft.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5B39.tmp\5B3A.tmp\5B3B.bat C:\Users\user\Desktop\minecraft.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\fsutil.exe fsutil dirty query C: |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /f /im taskmgr.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /f /im regedit.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\hal.dll /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\hal.dll /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winload.exe /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winload.exe /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winresume.exe /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winresume.exe /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winlogon.exe /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winlogon.exe /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\wininit.exe /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\wininit.exe /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\ntoskrnl.exe /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\ntoskrnl.exe /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\regedit.exe /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\regedit.exe /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\taskmgr.exe /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\taskmgr.exe /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\consent.exe /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\consent.exe /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\drivers /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\drivers /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\shutdown.exe /r /d y |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\shutdown.exe /grant everyone:F /t |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /f /im lsass.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\reg.exe reg delete HKLM /f |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: pcacli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\icacls.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: mpr.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: framedynos.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: dbghelp.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: winsta.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\taskkill.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: dui70.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: duser.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: windows.ui.immersive.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: dwmapi.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: dwrite.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: bcp47mrm.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: uianimation.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: dxgi.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: resourcepolicyclient.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: d3d11.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: d3d10warp.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: dxcore.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: dcomp.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\wlrmdr.exe |
Section loaded: wldp.dll |
|