Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286297733.000001F0111F5000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287538963.000001F011AFA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2618233200.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F011270000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: pservice.exe, 00000027.00000003.2531231225.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287503438.000001F011AEF000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537010055.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138656543.000001F011AEF000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: pservice.exe, 00000027.00000003.2531231225.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287503438.000001F011AEF000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537010055.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138656543.000001F011AEF000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crtKK |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286297733.000001F0111F5000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2618233200.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286297733.000001F0111F5000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138247513.000001F0112F6000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138282207.000001F0112FD000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2618233200.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: pservice.exe, 00000027.00000003.2531231225.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287503438.000001F011AEF000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537010055.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138656543.000001F011AEF000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/ |
Source: pservice.exe, 00000027.00000003.2531443435.000001F0112D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/4g |
Source: pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286297733.000001F0111F5000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287538963.000001F011AFA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2618233200.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F011270000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: pservice.exe, 00000027.00000003.3138463049.000001F0112E3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F0112C2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531231225.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287286552.000001F0112FE000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138247513.000001F0112F6000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537010055.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531406559.000001F0112F5000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287212937.000001F0112E8000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138282207.000001F0112FD000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F0112C2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531443435.000001F0112D9000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F0112C2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F0112D9000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: pservice.exe, 00000027.00000003.2531231225.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537010055.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlBy |
Source: pservice.exe, 00000027.00000003.3137674102.000001F0112B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlhttp://crl4.digicert.co |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286297733.000001F0111F5000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2618233200.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: pservice.exe, 00000027.00000003.3137674102.000001F0112C8000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F0112C8000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531443435.000001F0112D3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlche |
Source: pservice.exe, 00000027.00000003.2536923154.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2536642838.000001F011B06000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537335185.000001F011B07000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096 |
Source: pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0= |
Source: pservice.exe, 00000027.00000003.2531231225.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537010055.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0y |
Source: pservice.exe, 00000027.00000003.2531612650.000001F0112B2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl35 |
Source: pservice.exe, 00000027.00000003.2531231225.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537010055.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlZy |
Source: pservice.exe, 00000027.00000003.2531231225.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537010055.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crlxyI |
Source: pservice.exe, 00000027.00000003.2531443435.000001F0112D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/l |
Source: pservice.exe, 00000027.00000003.2537010055.000001F011AFA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531231225.000001F011AFA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com:80/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl |
Source: parsec-windows.exe, 0000000D.00000000.2203144262.000000000040A000.00000008.00000001.01000000.0000000A.sdmp, parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040A000.00000004.00000001.01000000.00000011.sdmp, parsec-vud.exe, 0000002D.00000000.2346150656.000000000040A000.00000008.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000000.2456937852.000000000040A000.00000008.00000001.01000000.00000017.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: pservice.exe, 00000027.00000002.3287466259.000001F011AEC000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531231225.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138396186.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537010055.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2618126507.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2532225566.000001F011B08000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531045774.000001F011B05000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137536300.000001F011AEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2537131193.000001F011AEE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com |
Source: pservice.exe, 00000027.00000003.2531443435.000001F0112D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/ |
Source: pservice.exe, 00000027.00000003.3137674102.000001F0112D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rh |
Source: pservice.exe, 00000027.00000002.3286410998.000001F01124A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxL |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286297733.000001F0111F5000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138247513.000001F0112F6000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138282207.000001F0112FD000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2618233200.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://ocsp.digicert.com0A |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286297733.000001F0111F5000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287538963.000001F011AFA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2618233200.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F011270000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://ocsp.digicert.com0C |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B0F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3287612130.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B1E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286297733.000001F0111F5000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137363925.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2618233200.000001F011B07000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://ocsp.digicert.com0X |
Source: pservice.exe, 00000027.00000003.3137674102.000001F0112D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRS |
Source: pservice.exe, 00000027.00000002.3287320221.000001F011AC0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com:80/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4 |
Source: pservice.exe, 00000027.00000003.2532225566.000001F011B08000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531045774.000001F011B05000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comC |
Source: pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertAssuredIDRootCA.crl |
Source: pservice.exe, 00000027.00000002.3287357243.000001F011ACC000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3138509714.000001F011ACB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.cr |
Source: pservice.exe, 00000027.00000003.2531612650.000001F0112C2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F0112C2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F0112C2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: pservice.exe, 00000027.00000003.2532225566.000001F011B08000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531045774.000001F011B05000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comu |
Source: parsec-windows.exe, 0000000D.00000002.2494270258.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000027.00000003.2496352326.000001F01129F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2515315073.000001F011B40000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2617887892.000001F011B50000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137674102.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.3137228223.000001F011B60000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000002.3286874234.000001F011259000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000027.00000003.2531612650.000001F01125C000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2448675906.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000041.00000002.2491857385.000000000040A000.00000004.00000001.01000000.00000017.sdmp | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: uu8v4UUzTU.tmp, 00000002.00000003.2276467221.00000000059D3000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.unicode.org/copyright.html |
Source: uu8v4UUzTU.tmp, 00000002.00000002.2293815599.000000000374D000.00000004.00000020.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000002.00000003.2286699133.0000000003720000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://beautifullyuncluttered.com/ |
Source: uu8v4UUzTU.tmp, 00000002.00000002.2293720265.0000000003710000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://beautifullyuncluttered.com/?CheckApp |
Source: uu8v4UUzTU.tmp, 00000002.00000002.2293720265.0000000003710000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ifconfig.me/ |
Source: uu8v4UUzTU.tmp, 00000002.00000003.2288649107.0000000000B0D000.00000004.00000020.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000002.00000003.2287035653.0000000000B0A000.00000004.00000020.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000002.00000002.2293088361.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ifconfig.me/ip |
Source: uu8v4UUzTU.tmp, 00000002.00000003.2288804175.0000000000A95000.00000004.00000020.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000002.00000002.2292586991.0000000000A9D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ifconfig.me/ip5.1ry |
Source: uu8v4UUzTU.exe, is-LQSSJ.tmp.2.dr | String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: parsec-vdd.exe, 00000041.00000002.2492098487.00000000005D1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://parsec.appURLUpdateInfohttps://parsec.app/changelog |
Source: parsec-windows.exe, 0000000D.00000003.2494039079.0000000000675000.00000004.00000020.00020000.00000000.sdmp, parsec-windows.exe, 0000000D.00000002.2494938332.0000000000675000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://parsec.appURLUpdateInfohttps://parsec.app/changelogURL:parsec |
Source: parsec-vud.exe, 0000002D.00000002.2450362899.0000000000518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://parsec.appURLUpdateInfohttps://parsec.app/changelogkernel32::Wow64EnableWow64FsRedirection(i |
Source: parsec-windows.exe, 0000000D.00000003.2494039079.0000000000675000.00000004.00000020.00020000.00000000.sdmp, parsec-windows.exe, 0000000D.00000002.2494938332.0000000000675000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002D.00000002.2450362899.0000000000518000.00000004.00000020.00020000.00000000.sdmp, parsec-vdd.exe, 00000041.00000002.2492098487.00000000005D1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://support.parsec.appInstallLocationNoModifyNoRepairPublisherParsec |
Source: uu8v4UUzTU.exe, 00000000.00000003.2029697537.000000007FB30000.00000004.00001000.00020000.00000000.sdmp, uu8v4UUzTU.exe, 00000000.00000003.2029324917.0000000002510000.00000004.00001000.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000002.00000000.2031188431.0000000000401000.00000020.00000001.01000000.00000004.sdmp | String found in binary or memory: https://www.innosetup.com/ |
Source: uu8v4UUzTU.exe, 00000000.00000003.2029697537.000000007FB30000.00000004.00001000.00020000.00000000.sdmp, uu8v4UUzTU.exe, 00000000.00000003.2029324917.0000000002510000.00000004.00001000.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000002.00000000.2031188431.0000000000401000.00000020.00000001.01000000.00000004.sdmp | String found in binary or memory: https://www.remobjects.com/ps |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F9D078 | 6_2_00F9D078 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F85134 | 6_2_00F85134 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FC8806 | 6_2_00FC8806 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FAD9EE | 6_2_00FAD9EE |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F7798C | 6_2_00F7798C |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F9AB24 | 6_2_00F9AB24 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F9DD64 | 6_2_00F9DD64 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FAF022 | 6_2_00FAF022 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FBF1EC | 6_2_00FBF1EC |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F831C8 | 6_2_00F831C8 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FC328C | 6_2_00FC328C |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F91288 | 6_2_00F91288 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F7C204 | 6_2_00F7C204 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FCE4D1 | 6_2_00FCE4D1 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FA541C | 6_2_00FA541C |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FB65F0 | 6_2_00FB65F0 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FCE5C0 | 6_2_00FCE5C0 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FC469D | 6_2_00FC469D |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F94640 | 6_2_00F94640 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FB87AC | 6_2_00FB87AC |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F8E8E0 | 6_2_00F8E8E0 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FA1984 | 6_2_00FA1984 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FA3BBC | 6_2_00FA3BBC |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F8DCAC | 6_2_00F8DCAC |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F77DE8 | 6_2_00F77DE8 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00FCDD60 | 6_2_00FCDD60 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F8DF78 | 6_2_00F8DF78 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 6_2_00F92F00 | 6_2_00F92F00 |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Code function: 13_2_0040755C | 13_2_0040755C |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Code function: 13_2_00406D85 | 13_2_00406D85 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD032130 | 39_2_00007FF7CD032130 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD036A28 | 39_2_00007FF7CD036A28 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD03EE70 | 39_2_00007FF7CD03EE70 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD039A8C | 39_2_00007FF7CD039A8C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD035F0C | 39_2_00007FF7CD035F0C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD039128 | 39_2_00007FF7CD039128 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD035D24 | 39_2_00007FF7CD035D24 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD035950 | 39_2_00007FF7CD035950 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD03557C | 39_2_00007FF7CD03557C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD03BDA0 | 39_2_00007FF7CD03BDA0 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD03E1C4 | 39_2_00007FF7CD03E1C4 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD041E0C | 39_2_00007FF7CD041E0C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD03C420 | 39_2_00007FF7CD03C420 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD040878 | 39_2_00007FF7CD040878 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD04A89C | 39_2_00007FF7CD04A89C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD03B8F0 | 39_2_00007FF7CD03B8F0 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD0464E0 | 39_2_00007FF7CD0464E0 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD035B38 | 39_2_00007FF7CD035B38 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD03A760 | 39_2_00007FF7CD03A760 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD035764 | 39_2_00007FF7CD035764 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD037784 | 39_2_00007FF7CD037784 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 39_2_00007FF7CD0373B8 | 39_2_00007FF7CD0373B8 |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Code function: 45_2_0040755C | 45_2_0040755C |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Code function: 45_2_00406D85 | 45_2_00406D85 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C2F4DD0 | 48_2_00007FF72C2F4DD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C304740 | 48_2_00007FF72C304740 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3168F0 | 48_2_00007FF72C3168F0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C303190 | 48_2_00007FF72C303190 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C350490 | 48_2_00007FF72C350490 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3014B0 | 48_2_00007FF72C3014B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C339D5C | 48_2_00007FF72C339D5C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C34DD94 | 48_2_00007FF72C34DD94 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C34FDF4 | 48_2_00007FF72C34FDF4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C308DD0 | 48_2_00007FF72C308DD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C347E1C | 48_2_00007FF72C347E1C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C348EE4 | 48_2_00007FF72C348EE4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C32FF5C | 48_2_00007FF72C32FF5C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C310FE0 | 48_2_00007FF72C310FE0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C32E090 | 48_2_00007FF72C32E090 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C2F7060 | 48_2_00007FF72C2F7060 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C34C95C | 48_2_00007FF72C34C95C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3139B0 | 48_2_00007FF72C3139B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3369B8 | 48_2_00007FF72C3369B8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C311A80 | 48_2_00007FF72C311A80 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C2F4A80 | 48_2_00007FF72C2F4A80 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C31EAA0 | 48_2_00007FF72C31EAA0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C32EAB4 | 48_2_00007FF72C32EAB4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C31DB70 | 48_2_00007FF72C31DB70 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C2F2BF0 | 48_2_00007FF72C2F2BF0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C341C70 | 48_2_00007FF72C341C70 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C340CDC | 48_2_00007FF72C340CDC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C339564 | 48_2_00007FF72C339564 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C33E544 | 48_2_00007FF72C33E544 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3435E4 | 48_2_00007FF72C3435E4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C34A24C | 48_2_00007FF72C34A24C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C32F5C8 | 48_2_00007FF72C32F5C8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C34065C | 48_2_00007FF72C34065C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C32E6A4 | 48_2_00007FF72C32E6A4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C33D6AC | 48_2_00007FF72C33D6AC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C311790 | 48_2_00007FF72C311790 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C343860 | 48_2_00007FF72C343860 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3388F0 | 48_2_00007FF72C3388F0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C32E8B0 | 48_2_00007FF72C32E8B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3148D0 | 48_2_00007FF72C3148D0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C332130 | 48_2_00007FF72C332130 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3391B8 | 48_2_00007FF72C3391B8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3401C8 | 48_2_00007FF72C3401C8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C31F260 | 48_2_00007FF72C31F260 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C2F3220 | 48_2_00007FF72C2F3220 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C32E294 | 48_2_00007FF72C32E294 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C34A24C | 48_2_00007FF72C34A24C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C330360 | 48_2_00007FF72C330360 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C2F43A0 | 48_2_00007FF72C2F43A0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C34B44C | 48_2_00007FF72C34B44C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C2FC4D0 | 48_2_00007FF72C2FC4D0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C32E4A0 | 48_2_00007FF72C32E4A0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 48_2_00007FF72C3364AC | 48_2_00007FF72C3364AC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AA68B0 | 51_2_00007FF7E5AA68B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A94740 | 51_2_00007FF7E5A94740 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ADF770 | 51_2_00007FF7E5ADF770 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A93190 | 51_2_00007FF7E5A93190 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A914B0 | 51_2_00007FF7E5A914B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A98DD0 | 51_2_00007FF7E5A98DD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AC1960 | 51_2_00007FF7E5AC1960 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AD2CE4 | 51_2_00007FF7E5AD2CE4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AD85E4 | 51_2_00007FF7E5AD85E4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AD751C | 51_2_00007FF7E5AD751C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AC9589 | 51_2_00007FF7E5AC9589 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AA48D0 | 51_2_00007FF7E5AA48D0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ACF8C8 | 51_2_00007FF7E5ACF8C8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ABD8C0 | 51_2_00007FF7E5ABD8C0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ADA72C | 51_2_00007FF7E5ADA72C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AA1790 | 51_2_00007FF7E5AA1790 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ABF78C | 51_2_00007FF7E5ABF78C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ABE2E4 | 51_2_00007FF7E5ABE2E4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A83220 | 51_2_00007FF7E5A83220 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AAD260 | 51_2_00007FF7E5AAD260 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AC61E8 | 51_2_00007FF7E5AC61E8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AC8120 | 51_2_00007FF7E5AC8120 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AAE190 | 51_2_00007FF7E5AAE190 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A8C4D0 | 51_2_00007FF7E5A8C4D0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A843A0 | 51_2_00007FF7E5A843A0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AD03DC | 51_2_00007FF7E5AD03DC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AD1370 | 51_2_00007FF7E5AD1370 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ABDED4 | 51_2_00007FF7E5ABDED4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A84DD0 | 51_2_00007FF7E5A84DD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ABEDF8 | 51_2_00007FF7E5ABEDF8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AC8D94 | 51_2_00007FF7E5AC8D94 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ACCD70 | 51_2_00007FF7E5ACCD70 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ACFD5C | 51_2_00007FF7E5ACFD5C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ADF0D4 | 51_2_00007FF7E5ADF0D4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ABE0E0 | 51_2_00007FF7E5ABE0E0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ADD074 | 51_2_00007FF7E5ADD074 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A87060 | 51_2_00007FF7E5A87060 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AA0FE0 | 51_2_00007FF7E5AA0FE0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AD2F60 | 51_2_00007FF7E5AD2F60 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ABDAC4 | 51_2_00007FF7E5ABDAC4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AA1A80 | 51_2_00007FF7E5AA1A80 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A84A80 | 51_2_00007FF7E5A84A80 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AA39B0 | 51_2_00007FF7E5AA39B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AC89E8 | 51_2_00007FF7E5AC89E8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ABDCD0 | 51_2_00007FF7E5ABDCD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5AC5CDC | 51_2_00007FF7E5AC5CDC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ACDC40 | 51_2_00007FF7E5ACDC40 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ADBC3C | 51_2_00007FF7E5ADBC3C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5A82BF0 | 51_2_00007FF7E5A82BF0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 51_2_00007FF7E5ABFB90 | 51_2_00007FF7E5ABFB90 |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Code function: 65_2_0040755C | 65_2_0040755C |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Code function: 65_2_00406D85 | 65_2_00406D85 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618181960 | 71_2_00007FF618181960 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF6181889E8 | 71_2_00007FF6181889E8 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618192CE4 | 71_2_00007FF618192CE4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618158DD0 | 71_2_00007FF618158DD0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618153190 | 71_2_00007FF618153190 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF6181514B0 | 71_2_00007FF6181514B0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61814C4D0 | 71_2_00007FF61814C4D0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61819F770 | 71_2_00007FF61819F770 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618154740 | 71_2_00007FF618154740 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF6181668B0 | 71_2_00007FF6181668B0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF6181639B0 | 71_2_00007FF6181639B0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618144A80 | 71_2_00007FF618144A80 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618161A80 | 71_2_00007FF618161A80 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61817DAC4 | 71_2_00007FF61817DAC4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61817FB90 | 71_2_00007FF61817FB90 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618142BF0 | 71_2_00007FF618142BF0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61818DC40 | 71_2_00007FF61818DC40 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61819BC3C | 71_2_00007FF61819BC3C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618185CDC | 71_2_00007FF618185CDC |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61817DCD0 | 71_2_00007FF61817DCD0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61818FD5C | 71_2_00007FF61818FD5C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61818CD70 | 71_2_00007FF61818CD70 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618188D94 | 71_2_00007FF618188D94 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618144DD0 | 71_2_00007FF618144DD0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61817EDF8 | 71_2_00007FF61817EDF8 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61817DED4 | 71_2_00007FF61817DED4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618192F60 | 71_2_00007FF618192F60 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618160FE0 | 71_2_00007FF618160FE0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618147060 | 71_2_00007FF618147060 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61819D074 | 71_2_00007FF61819D074 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61817E0E0 | 71_2_00007FF61817E0E0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61819F0D4 | 71_2_00007FF61819F0D4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618188120 | 71_2_00007FF618188120 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61816E190 | 71_2_00007FF61816E190 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF6181861E8 | 71_2_00007FF6181861E8 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618143220 | 71_2_00007FF618143220 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61816D260 | 71_2_00007FF61816D260 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61817E2E4 | 71_2_00007FF61817E2E4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618191370 | 71_2_00007FF618191370 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF6181443A0 | 71_2_00007FF6181443A0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF6181903DC | 71_2_00007FF6181903DC |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61819751C | 71_2_00007FF61819751C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618189589 | 71_2_00007FF618189589 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF6181985E4 | 71_2_00007FF6181985E4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61819A72C | 71_2_00007FF61819A72C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61817F78C | 71_2_00007FF61817F78C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF618161790 | 71_2_00007FF618161790 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61817D8C0 | 71_2_00007FF61817D8C0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF61818F8C8 | 71_2_00007FF61818F8C8 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 71_2_00007FF6181648D0 | 71_2_00007FF6181648D0 |
Source: unknown | Process created: C:\Users\user\Desktop\uu8v4UUzTU.exe "C:\Users\user\Desktop\uu8v4UUzTU.exe" | |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Process created: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp "C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp" /SL5="$1043C,49640288,887296,C:\Users\user\Desktop\uu8v4UUzTU.exe" | |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z.bat" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\PSecWin\7z.exe "C:\Users\user\AppData\Roaming\PSecWin\7z.exe" x -aoa "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z" -p"fa073db961c" -o"C:\Users\user\AppData\Roaming\PSecWin\" | |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C del "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z.bat" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C del "SoundNight.7z" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "cmd" /C "C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-kill-parsec.vbs" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" control Parsec 200 | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /F /IM parsecd.exe | |
Source: C:\Windows\SysWOW64\taskkill.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-remove.vbs" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" stop Parsec | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" delete Parsec | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\firewall-remove.vbs" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=Parsec | |
Source: C:\Windows\SysWOW64\netsh.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=parsec.exe | |
Source: C:\Windows\SysWOW64\netsh.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=parsecd.exe | |
Source: C:\Windows\SysWOW64\netsh.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\legacy-cleanup.vbs" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /delete /tn ParsecTeams /f | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-install.vbs" "C:\Program Files\Parsec\pservice.exe" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" create Parsec binPath= "\"C:\Program Files\Parsec\pservice.exe\"" start= auto type= interact type= own | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" start Parsec | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Program Files\Parsec\pservice.exe "C:\Program Files\Parsec\pservice.exe" | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\firewall-add.vbs" "C:\Program Files\Parsec\parsecd.exe" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall add rule name=Parsec dir=in action=allow program="C:\Program Files\Parsec\parsecd.exe" enable=yes profile=public,private,domain | |
Source: C:\Windows\SysWOW64\netsh.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec\vusb\parsec-vud.exe" /S | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec\vusb\parsec-vud.exe "C:\Program Files\Parsec\vusb\parsec-vud.exe" /S | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe" --find-hwid --hardware-id VUSBA | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe "C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe" --find-hwid --hardware-id VUSBA | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Parsec Virtual USB Adapter Driver\vusbinstall.bat"" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --create-device-node --hardware-id Root\Parsec\VUSBA --class-name USB --class-guid "36fc9e60-c465-11cf-8056-444553540000" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --install-driver --inf-path ".\parsecvusba\parsecvusba.inf" | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k DcomLaunch -p -s DeviceInstall | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{0bfc15e2-0e86-4044-8941-72f0e156798b}\parsecvusba.inf" "9" "464910f03" "0000000000000158" "WinSta0\Default" "0000000000000160" "208" "C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvusba" | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "2" "201" "ROOT\USB\0000" "C:\Windows\System32\DriverStore\FileRepository\parsecvusba.inf_amd64_dae154cc0d6f64e9\parsecvusba.inf" "oem4.inf:*:*:0.2.8.0:Root\Parsec\VUSBA," "464910f03" "0000000000000158" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --inf-default-install --inf-path ".\parsecvirtualds\parsecvirtualds.inf" | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{a3ae9bde-474f-8049-a9b1-c003314cfbdb}\parsecvirtualds.inf" "9" "43799a85b" "0000000000000170" "WinSta0\Default" "0000000000000158" "208" "C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvirtualds" | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "8" "4" "C:\Windows\System32\DriverStore\FileRepository\parsecvirtualds.inf_amd64_dabce1c8ac909510\parsecvirtualds.inf" "0" "43799a85b" "0000000000000158" "WinSta0\Default" | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process created: C:\Windows\System32\runonce.exe "C:\Windows\system32\runonce.exe" -r | |
Source: C:\Windows\System32\runonce.exe | Process created: C:\Windows\System32\grpconv.exe "C:\Windows\System32\grpconv.exe" -o | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "8" "4" "C:\Windows\System32\DriverStore\FileRepository\parsecvirtualds.inf_amd64_dabce1c8ac909510\parsecvirtualds.inf" "0" "4fea13f63" "0000000000000190" "WinSta0\Default" | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec\vdd\parsec-vdd.exe" /S | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec\vdd\parsec-vdd.exe "C:\Program Files\Parsec\vdd\parsec-vdd.exe" /S | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: C:\Windows\SysWOW64\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" | |
Source: C:\Windows\SysWOW64\wevtutil.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wevtutil.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" /fromwow64 | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Parsec Virtual Display Driver\vddinstall.bat"" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --remove-device-node --hardware-id Root\Parsec\VDA --class-guid "4D36E968-E325-11CE-BFC1-08002BE10318" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --create-device-node --class-name Display --class-guid "4D36E968-E325-11CE-BFC1-08002BE10318" --hardware-id Root\Parsec\VDA | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --install-driver --inf-path ".\driver\mm.inf" | |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Process created: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp "C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp" /SL5="$1043C,49640288,887296,C:\Users\user\Desktop\uu8v4UUzTU.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z.bat" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C del "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z.bat" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C del "SoundNight.7z" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "cmd" /C "C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\PSecWin\7z.exe "C:\Users\user\AppData\Roaming\PSecWin\7z.exe" x -aoa "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z" -p"fa073db961c" -o"C:\Users\user\AppData\Roaming\PSecWin\" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-kill-parsec.vbs" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-remove.vbs" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\firewall-remove.vbs" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\legacy-cleanup.vbs" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-install.vbs" "C:\Program Files\Parsec\pservice.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\firewall-add.vbs" "C:\Program Files\Parsec\parsecd.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec\vusb\parsec-vud.exe" /S | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec\vdd\parsec-vdd.exe" /S | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" /fromwow64 | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" control Parsec 200 | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /F /IM parsecd.exe | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" stop Parsec | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" delete Parsec | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=Parsec | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=parsec.exe | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=parsecd.exe | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /delete /tn ParsecTeams /f | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" create Parsec binPath= "\"C:\Program Files\Parsec\pservice.exe\"" start= auto type= interact type= own | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" start Parsec | |
Source: C:\Program Files\Parsec\pservice.exe | Process created: unknown unknown | |
Source: C:\Program Files\Parsec\pservice.exe | Process created: unknown unknown | |
Source: C:\Program Files\Parsec\pservice.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall add rule name=Parsec dir=in action=allow program="C:\Program Files\Parsec\parsecd.exe" enable=yes profile=public,private,domain | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec\vusb\parsec-vud.exe "C:\Program Files\Parsec\vusb\parsec-vud.exe" /S | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe" --find-hwid --hardware-id VUSBA | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Parsec Virtual USB Adapter Driver\vusbinstall.bat"" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe "C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe" --find-hwid --hardware-id VUSBA | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --create-device-node --hardware-id Root\Parsec\VUSBA --class-name USB --class-guid "36fc9e60-c465-11cf-8056-444553540000" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --install-driver --inf-path ".\parsecvusba\parsecvusba.inf" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --inf-default-install --inf-path ".\parsecvirtualds\parsecvirtualds.inf" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{0bfc15e2-0e86-4044-8941-72f0e156798b}\parsecvusba.inf" "9" "464910f03" "0000000000000158" "WinSta0\Default" "0000000000000160" "208" "C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvusba" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "2" "201" "ROOT\USB\0000" "C:\Windows\System32\DriverStore\FileRepository\parsecvusba.inf_amd64_dae154cc0d6f64e9\parsecvusba.inf" "oem4.inf:*:*:0.2.8.0:Root\Parsec\VUSBA," "464910f03" "0000000000000158" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{a3ae9bde-474f-8049-a9b1-c003314cfbdb}\parsecvirtualds.inf" "9" "43799a85b" "0000000000000170" "WinSta0\Default" "0000000000000158" "208" "C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvirtualds" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "8" "4" "C:\Windows\System32\DriverStore\FileRepository\parsecvirtualds.inf_amd64_dabce1c8ac909510\parsecvirtualds.inf" "0" "43799a85b" "0000000000000158" "WinSta0\Default" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "8" "4" "C:\Windows\System32\DriverStore\FileRepository\parsecvirtualds.inf_amd64_dabce1c8ac909510\parsecvirtualds.inf" "0" "4fea13f63" "0000000000000190" "WinSta0\Default" | |
Source: C:\Windows\System32\svchost.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\svchost.exe | Process created: unknown unknown | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process created: C:\Windows\System32\runonce.exe "C:\Windows\system32\runonce.exe" -r | |
Source: C:\Windows\System32\runonce.exe | Process created: C:\Windows\System32\grpconv.exe "C:\Windows\System32\grpconv.exe" -o | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec\vdd\parsec-vdd.exe "C:\Program Files\Parsec\vdd\parsec-vdd.exe" /S | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: C:\Windows\SysWOW64\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Parsec Virtual Display Driver\vddinstall.bat"" | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\wevtutil.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" /fromwow64 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --remove-device-node --hardware-id Root\Parsec\VDA --class-guid "4D36E968-E325-11CE-BFC1-08002BE10318" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --create-device-node --class-name Display --class-guid "4D36E968-E325-11CE-BFC1-08002BE10318" --hardware-id Root\Parsec\VDA | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --install-driver --inf-path ".\driver\mm.inf" | |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: winhttpcom.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ifmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasmontr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasapi32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mfc42u.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: authfwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcmonitor.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3cfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3api.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: onex.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ncrypt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappprxy.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ntasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: hnetmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netshell.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netsetupapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netiohlp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: httpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: activeds.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: polstore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshwfp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cabinet.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2pnetsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2p.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rpcnsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: whhelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlancfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlanapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wshelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wevtapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: peerdistsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wcmapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mobilenetworking.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprmsg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ifmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasmontr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasapi32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mfc42u.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: authfwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcmonitor.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3cfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3api.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: onex.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ncrypt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappprxy.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ntasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: hnetmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netshell.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netsetupapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netiohlp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: httpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: activeds.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: polstore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshwfp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cabinet.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2pnetsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2p.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rpcnsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: whhelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlancfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlanapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wshelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wevtapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: peerdistsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wcmapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mobilenetworking.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprmsg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ifmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasmontr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasapi32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mfc42u.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: authfwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcmonitor.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3cfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3api.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: onex.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ncrypt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappprxy.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ntasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: hnetmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netshell.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netsetupapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netiohlp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: httpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: activeds.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: polstore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshwfp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cabinet.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2pnetsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2p.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rpcnsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: whhelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlancfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlanapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wshelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wevtapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: peerdistsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wcmapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mobilenetworking.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprmsg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: wtsapi32.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: msi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: sas.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: wldp.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: profapi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\SystemEventsBrokerClient.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-GF1GP.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-E9NUA.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-6QS3I.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\wiashext.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\rdvgocl32.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\wlanext.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\RdpSaUacHelper.exe (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-LQSSJ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-ETRQM.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-UEG3C.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-MAETF.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\pservice.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\TrustedSignalCredProv.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-4URGO.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Users\user\AppData\Local\Temp\nsj59D8.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\vusb\parsec-vud.exe | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Users\user\AppData\Local\Temp\nsg84FF.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-RT5NS.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\kbdarmty.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\Windows.UI.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-9PV08.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\IEAdvpack.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-E0QD0.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-2UJJU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\networkhelper.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\cryptdlg.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\MFWMAAEC.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\WSClient.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\Windows.ApplicationModel.ConversationalAgent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\VscMgrPS.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-DPGTR.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\xpsservices.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-JR54E.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\kbd101b.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-9HF18.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\mfc140enu.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-CR69T.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-I559Q.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-MRTFO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\UserDataAccessRes.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-O65TT.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{a3ae9bde-474f-8049-a9b1-c003314cfbdb}\SET7030.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\icuin.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\KBDA3.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\xwreg.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\7z.exe (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{99c328e9-049a-fe42-a35c-67fa3e25e77d}\SET8ABC.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\VAN.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-PJ6TS.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-2DG57.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\wups.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-B9257.tmp | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | File created: C:\Windows\System32\DriverStore\Temp\{18245a7a-9319-bd4f-bd5f-a24ba1e93bca}\parsecvusba.sys (copy) | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | File created: C:\Windows\System32\DriverStore\Temp\{7106dfa1-62ec-4647-bfd5-42198dd8ac12}\SET70EC.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\LockAppBroker.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\MCRecvSrc.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\socialapis.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\netevent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{0bfc15e2-0e86-4044-8941-72f0e156798b}\parsecvusba.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\dskquoui.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\gp548-win64-mingw.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\netlogon.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-CEP95.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-2OR81.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\TpmTool.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-KU451.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\skel\parsecd-150-93b.dll | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-CFLCO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Users\user\AppData\Local\Temp\nsj258A.tmp\ApplicationID.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-JBM9N.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-GTN75.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\teams.exe | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | File created: C:\Windows\System32\DriverStore\Temp\{18245a7a-9319-bd4f-bd5f-a24ba1e93bca}\SET638E.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\runonce.exe (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvusba\parsecvusba.sys | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-BT11A.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-3KUTO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\dmcfgutils.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-IQ3DU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\unins000.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\ws2help.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\shrpubw.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\tapiui.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Users\user\AppData\Local\Temp\nsj59D8.tmp\UserInfo.dll | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{99c328e9-049a-fe42-a35c-67fa3e25e77d}\mm.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\mcbuilder.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Local\Temp\is-O9NMT.tmp\_isetup\_setup64.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\MP43DECD.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | File created: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\sscore.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-HI204.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\verifier.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-ADU4M.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-0HD4S.tmp | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | File created: C:\Windows\System32\DriverStore\Temp\{7106dfa1-62ec-4647-bfd5-42198dd8ac12}\parsecvirtualds.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-NSRV7.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\getuname.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Program Files\Parsec Virtual Display Driver\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Users\user\AppData\Local\Temp\nsj258A.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-V0EDB.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-O1M5L.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-G3B26.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-S2KJ6.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Users\user\AppData\Local\Temp\nsg84FF.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-KU5LP.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\iesysprep.dll (copy) | Jump to dropped file |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | File created: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-3JPOJ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-VK3B0.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-M8LS1.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvirtualds\parsecvirtualds.sys | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-R541B.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\kbdibm02.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-514OT.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Users\user\AppData\Local\Temp\nsj258A.tmp\nsDialogs.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Users\user\AppData\Local\Temp\nsj258A.tmp\System.dll | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{0bfc15e2-0e86-4044-8941-72f0e156798b}\SET614C.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\SyncInfrastructureps.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-66C2H.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Users\user\AppData\Local\Temp\nsj59D8.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-OGENO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\parsecd.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-IH0UT.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Program Files\Parsec Virtual Display Driver\driver\mm.dll | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{a3ae9bde-474f-8049-a9b1-c003314cfbdb}\parsecvirtualds.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\7z.dll (copy) | Jump to dropped file |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec\pservice.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec\pservice.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\grpconv.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\grpconv.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\grpconv.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\grpconv.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\SystemEventsBrokerClient.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-GF1GP.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-E9NUA.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-6QS3I.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\wiashext.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\rdvgocl32.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\RdpSaUacHelper.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\wlanext.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-LQSSJ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-ETRQM.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-UEG3C.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-MAETF.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\TrustedSignalCredProv.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-4URGO.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsj59D8.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsg84FF.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-RT5NS.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\kbdarmty.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\Windows.UI.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-9PV08.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\IEAdvpack.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-E0QD0.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\cryptdlg.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\networkhelper.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\MFWMAAEC.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\Windows.ApplicationModel.ConversationalAgent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\WSClient.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\VscMgrPS.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-DPGTR.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\xpsservices.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-JR54E.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\kbd101b.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-9HF18.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Program Files\Parsec\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\mfc140enu.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-CR69T.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-I559Q.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\UserDataAccessRes.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-MRTFO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-O65TT.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{a3ae9bde-474f-8049-a9b1-c003314cfbdb}\SET7030.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\icuin.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\KBDA3.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\xwreg.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{99c328e9-049a-fe42-a35c-67fa3e25e77d}\SET8ABC.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\VAN.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-PJ6TS.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\wups.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-2DG57.tmp | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{7106dfa1-62ec-4647-bfd5-42198dd8ac12}\SET70EC.tmp | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{18245a7a-9319-bd4f-bd5f-a24ba1e93bca}\parsecvusba.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-B9257.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\LockAppBroker.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\MCRecvSrc.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\netevent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\socialapis.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{0bfc15e2-0e86-4044-8941-72f0e156798b}\parsecvusba.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\gp548-win64-mingw.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\dskquoui.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\netlogon.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-CEP95.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\TpmTool.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-2OR81.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Program Files\Parsec\skel\parsecd-150-93b.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-KU451.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual USB Adapter Driver\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-CFLCO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsj258A.tmp\ApplicationID.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-JBM9N.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-GTN75.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Program Files\Parsec\teams.exe | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{18245a7a-9319-bd4f-bd5f-a24ba1e93bca}\SET638E.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\runonce.exe (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvusba\parsecvusba.sys | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-BT11A.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\dmcfgutils.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-3KUTO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-IQ3DU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\ws2help.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\unins000.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\shrpubw.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\tapiui.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsj59D8.tmp\UserInfo.dll | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{99c328e9-049a-fe42-a35c-67fa3e25e77d}\mm.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\mcbuilder.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-O9NMT.tmp\_isetup\_setup64.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\MP43DECD.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\sscore.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\verifier.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-HI204.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-ADU4M.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-0HD4S.tmp | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{7106dfa1-62ec-4647-bfd5-42198dd8ac12}\parsecvirtualds.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-NSRV7.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\getuname.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual Display Driver\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsj258A.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-V0EDB.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-O1M5L.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-G3B26.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-S2KJ6.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsg84FF.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-KU5LP.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\iesysprep.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-3JPOJ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-VK3B0.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-M8LS1.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvirtualds\parsecvirtualds.sys | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-R541B.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\kbdibm02.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-514OT.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsj258A.tmp\nsDialogs.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsj258A.tmp\System.dll | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{0bfc15e2-0e86-4044-8941-72f0e156798b}\SET614C.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\SyncInfrastructureps.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-66C2H.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsj59D8.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-OGENO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Program Files\Parsec\parsecd.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-IH0UT.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual Display Driver\driver\mm.dll | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{a3ae9bde-474f-8049-a9b1-c003314cfbdb}\parsecvirtualds.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-ADGVN.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\7z.dll (copy) | Jump to dropped file |