Source: unknown | Process created: C:\Users\user\Desktop\minecraft.exe "C:\Users\user\Desktop\minecraft.exe" | |
Source: C:\Users\user\Desktop\minecraft.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5B39.tmp\5B3A.tmp\5B3B.bat C:\Users\user\Desktop\minecraft.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\fsutil.exe fsutil dirty query C: | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /f /im taskmgr.exe | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /f /im regedit.exe | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\hal.dll /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\hal.dll /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winload.exe /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winload.exe /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winresume.exe /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winresume.exe /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winlogon.exe /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winlogon.exe /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\wininit.exe /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\wininit.exe /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\ntoskrnl.exe /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\ntoskrnl.exe /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\regedit.exe /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\regedit.exe /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\taskmgr.exe /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\taskmgr.exe /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\consent.exe /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\consent.exe /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\drivers /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\drivers /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\shutdown.exe /r /d y | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\shutdown.exe /grant everyone:F /t | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /f /im lsass.exe | |
Source: unknown | Process created: C:\Windows\System32\wlrmdr.exe -s -1 -f 2 -t Your PC will automatically restart in one minute -m Windows ran into a problem and needs to restart. You should close this message now and save your work. -a 3 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\reg.exe reg delete HKLM /f | |
Source: C:\Users\user\Desktop\minecraft.exe | Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5B39.tmp\5B3A.tmp\5B3B.bat C:\Users\user\Desktop\minecraft.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\fsutil.exe fsutil dirty query C: | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /f /im taskmgr.exe | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /f /im regedit.exe | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\hal.dll /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\hal.dll /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winload.exe /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winload.exe /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winresume.exe /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winresume.exe /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\winlogon.exe /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\winlogon.exe /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\wininit.exe /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\wininit.exe /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\ntoskrnl.exe /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\ntoskrnl.exe /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\regedit.exe /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\regedit.exe /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\taskmgr.exe /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\taskmgr.exe /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\consent.exe /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\consent.exe /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\drivers /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\drivers /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\takeown.exe takeown /f C:\Windows\System32\shutdown.exe /r /d y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\icacls.exe icacls C:\Windows\System32\shutdown.exe /grant everyone:F /t | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /f /im lsass.exe | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\reg.exe reg delete HKLM /f | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\minecraft.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\takeown.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\takeown.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\icacls.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\taskkill.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: dui70.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: duser.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: xmllite.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: windows.ui.immersive.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: dwrite.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: bcp47mrm.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: uianimation.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: dxgi.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: resourcepolicyclient.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: d3d11.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: d3d10warp.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: dxcore.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: dcomp.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: textinputframework.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: coremessaging.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: coremessaging.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: textshaping.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\wlrmdr.exe | Section loaded: wldp.dll | |