Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575054832.000001988FF65000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743387928.000001989087F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743298668.0000019890869000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337367644.000001989086D000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742435199.0000019890869000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309499408.0000019890894000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3576139520.000001989086E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337299753.000001989087F000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742558824.0000019890081000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575628914.000001988FFED000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743225180.0000019890085000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742804940.0000019890084000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575054832.000001988FF65000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743387928.000001989087F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575628914.000001988FFED000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337299753.000001989087F000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2743298668.0000019890878000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575054832.000001988FF65000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743387928.000001989087F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3576173174.0000019890878000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742435199.0000019890878000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337299753.000001989087F000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: drvinst.exe, 00000037.00000003.2039083129.000002B48D596000.00000004.00000020.00020000.00000000.sdmp, drvinst.exe, 00000037.00000003.2038432096.000002B48D588000.00000004.00000020.00020000.00000000.sdmp, drvinst.exe, 00000037.00000003.2036630983.000002B48D59B000.00000004.00000020.00020000.00000000.sdmp, drvinst.exe, 00000037.00000002.2039476468.000002B48D598000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.microsoft |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575054832.000001988FF65000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743387928.000001989087F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743298668.0000019890869000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337367644.000001989086D000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742435199.0000019890869000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309499408.0000019890894000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3576139520.000001989086E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337299753.000001989087F000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742558824.0000019890081000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575628914.000001988FFED000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743225180.0000019890085000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742804940.0000019890084000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575054832.000001988FF65000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743387928.000001989087F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575628914.000001988FFED000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337299753.000001989087F000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: parsec-vud.exe.12.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742558824.0000019890081000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575628914.000001988FFED000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743225180.0000019890085000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742804940.0000019890084000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0= |
Source: parsec-windows.exe, 0000000C.00000000.1878859711.000000000040A000.00000008.00000001.01000000.0000000A.sdmp, parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040A000.00000004.00000001.01000000.00000011.sdmp, parsec-vud.exe, 0000002E.00000000.2008553821.000000000040A000.00000008.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-vdd.exe, 00000042.00000000.2095284861.000000000040A000.00000008.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: pservice.exe, 00000028.00000003.3336997303.0000019890056000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.0000019890056000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575835781.0000019890056000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3576074424.0000019890860000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rh |
Source: pservice.exe, 00000028.00000002.3576040619.0000019890087000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742558824.0000019890081000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743225180.0000019890085000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742804940.0000019890084000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575175842.000001988FFDA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxL |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742558824.0000019890081000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575628914.000001988FFED000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743225180.0000019890085000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742804940.0000019890084000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://ocsp.digicert.com0 |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2743298668.0000019890878000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575054832.000001988FF65000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743387928.000001989087F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3576173174.0000019890878000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742435199.0000019890878000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337299753.000001989087F000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575054832.000001988FF65000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743387928.000001989087F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743298668.0000019890869000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337367644.000001989086D000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742435199.0000019890869000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309499408.0000019890894000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3576139520.000001989086E000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337299753.000001989087F000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575054832.000001988FF65000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743387928.000001989087F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575628914.000001988FFED000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3337299753.000001989087F000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: pservice.exe, 00000028.00000003.2742828975.000001989006A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRS |
Source: pservice.exe, 00000028.00000002.3576074424.0000019890860000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com1.3.6.1.5.5.7.48.2http://cacerts.digicert.com/DigiCertTrustedRootG4.crtFj |
Source: pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575628914.000001988FFED000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertAssuredIDRootCA.crlv |
Source: pservice.exe, 00000028.00000003.2742558824.000001989004D000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3336997303.000001989004D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.cr |
Source: pservice.exe, 00000028.00000003.2742558824.000001989004D000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.3336997303.000001989004D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: parsec-windows.exe, 0000000C.00000002.2126070552.000000000040A000.00000004.00000001.01000000.0000000A.sdmp, pservice.exe, 00000028.00000003.2742558824.000001988FFEA000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309422964.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2228501112.00000198908B3000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742558824.0000019890081000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2309199634.00000198909A2000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2126735399.000001989002F000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000002.3575628914.000001988FFED000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2743225180.0000019890085000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742804940.0000019890084000.00000004.00000020.00020000.00000000.sdmp, pservice.exe, 00000028.00000003.2742828975.000001988FFEB000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092202681.000000000040D000.00000004.00000001.01000000.00000011.sdmp, parsec-vdd.exe, 00000042.00000002.2124004520.000000000040A000.00000004.00000001.01000000.00000018.sdmp, parsec-windows.exe.5.dr, parsec-vud.exe.12.dr | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: uu8v4UUzTU.tmp, 00000001.00000003.1946267856.0000000005AA3000.00000004.00001000.00020000.00000000.sdmp, is-BUN5H.tmp.1.dr | String found in binary or memory: http://www.unicode.org/copyright.html |
Source: uu8v4UUzTU.tmp, 00000001.00000003.1869309057.0000000003A58000.00000004.00000020.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000001.00000002.2154440531.0000000003A93000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://beautifullyuncluttered.com/ |
Source: uu8v4UUzTU.tmp, 00000001.00000003.1869309057.0000000003A58000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://beautifullyuncluttered.com/?CheckApp |
Source: uu8v4UUzTU.tmp, 00000001.00000003.1869309057.0000000003A58000.00000004.00000020.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000001.00000002.2154440531.0000000003A93000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://beautifullyuncluttered.com/L |
Source: uu8v4UUzTU.tmp, 00000001.00000003.1960296249.00000000008BD000.00000004.00000020.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000001.00000003.1956522073.00000000008BB000.00000004.00000020.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000001.00000002.2153836962.00000000008BE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ifconfig.me/G |
Source: uu8v4UUzTU.tmp, 00000001.00000002.2154346874.00000000039C0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ifconfig.me/ip |
Source: uu8v4UUzTU.tmp, 00000001.00000003.1960625837.0000000000854000.00000004.00000020.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000001.00000002.2153690668.0000000000854000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ifconfig.me/ip5.1ry |
Source: uu8v4UUzTU.exe, is-G92OK.tmp.1.dr | String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: parsec-vdd.exe, 00000042.00000002.2124360355.0000000000618000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://parsec.appURLUpdateInfohttps://parsec.app/changelog |
Source: parsec-windows.exe, 0000000C.00000002.2126538465.00000000007D3000.00000004.00000020.00020000.00000000.sdmp, parsec-windows.exe, 0000000C.00000003.2125830286.00000000007D3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://parsec.appURLUpdateInfohttps://parsec.app/changelogURL:parsec |
Source: parsec-vud.exe, 0000002E.00000002.2092532699.0000000000608000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://parsec.appURLUpdateInfohttps://parsec.app/changelogkernel32::Wow64EnableWow64FsRedirection(i |
Source: parsec-windows.exe, 0000000C.00000002.2126538465.00000000007D3000.00000004.00000020.00020000.00000000.sdmp, parsec-windows.exe, 0000000C.00000003.2125830286.00000000007D3000.00000004.00000020.00020000.00000000.sdmp, parsec-vud.exe, 0000002E.00000002.2092532699.0000000000608000.00000004.00000020.00020000.00000000.sdmp, parsec-vdd.exe, 00000042.00000002.2124360355.0000000000618000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://support.parsec.appInstallLocationNoModifyNoRepairPublisherParsec |
Source: uu8v4UUzTU.exe, 00000000.00000003.1717417935.000000007FB30000.00000004.00001000.00020000.00000000.sdmp, uu8v4UUzTU.exe, 00000000.00000003.1716990180.0000000002560000.00000004.00001000.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000001.00000000.1718977411.0000000000401000.00000020.00000001.01000000.00000004.sdmp, uu8v4UUzTU.tmp.0.dr | String found in binary or memory: https://www.innosetup.com/ |
Source: uu8v4UUzTU.exe, 00000000.00000003.1717417935.000000007FB30000.00000004.00001000.00020000.00000000.sdmp, uu8v4UUzTU.exe, 00000000.00000003.1716990180.0000000002560000.00000004.00001000.00020000.00000000.sdmp, uu8v4UUzTU.tmp, 00000001.00000000.1718977411.0000000000401000.00000020.00000001.01000000.00000004.sdmp, uu8v4UUzTU.tmp.0.dr | String found in binary or memory: https://www.remobjects.com/ps |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0043D078 | 5_2_0043D078 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_00425134 | 5_2_00425134 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_00468806 | 5_2_00468806 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0044D9EE | 5_2_0044D9EE |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0041798C | 5_2_0041798C |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0043AB24 | 5_2_0043AB24 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0043DD64 | 5_2_0043DD64 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0044F022 | 5_2_0044F022 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_004231C8 | 5_2_004231C8 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0045F1EC | 5_2_0045F1EC |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0041C204 | 5_2_0041C204 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0046328C | 5_2_0046328C |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_00431288 | 5_2_00431288 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0044541C | 5_2_0044541C |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0046E4D1 | 5_2_0046E4D1 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0046E5C0 | 5_2_0046E5C0 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_004565F0 | 5_2_004565F0 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_00434640 | 5_2_00434640 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0046469D | 5_2_0046469D |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_004587AC | 5_2_004587AC |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0042E8E0 | 5_2_0042E8E0 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_00441984 | 5_2_00441984 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_00443BBC | 5_2_00443BBC |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0042DCAC | 5_2_0042DCAC |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0046DD60 | 5_2_0046DD60 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_00417DE8 | 5_2_00417DE8 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_0042DF78 | 5_2_0042DF78 |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Code function: 5_2_00432F00 | 5_2_00432F00 |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Code function: 12_2_0040755C | 12_2_0040755C |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Code function: 12_2_00406D85 | 12_2_00406D85 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC022130 | 40_2_00007FF7EC022130 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC029128 | 40_2_00007FF7EC029128 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC025D24 | 40_2_00007FF7EC025D24 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC025950 | 40_2_00007FF7EC025950 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC02557C | 40_2_00007FF7EC02557C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC02BDA0 | 40_2_00007FF7EC02BDA0 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC02E1C4 | 40_2_00007FF7EC02E1C4 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC031E0C | 40_2_00007FF7EC031E0C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC026A28 | 40_2_00007FF7EC026A28 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC02EE70 | 40_2_00007FF7EC02EE70 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC029A8C | 40_2_00007FF7EC029A8C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC025F0C | 40_2_00007FF7EC025F0C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC025B38 | 40_2_00007FF7EC025B38 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC02A760 | 40_2_00007FF7EC02A760 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC025764 | 40_2_00007FF7EC025764 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC027784 | 40_2_00007FF7EC027784 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC0273B8 | 40_2_00007FF7EC0273B8 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC02C420 | 40_2_00007FF7EC02C420 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC030878 | 40_2_00007FF7EC030878 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC03A89C | 40_2_00007FF7EC03A89C |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC02B8F0 | 40_2_00007FF7EC02B8F0 |
Source: C:\Program Files\Parsec\pservice.exe | Code function: 40_2_00007FF7EC0364E0 | 40_2_00007FF7EC0364E0 |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Code function: 46_2_0040755C | 46_2_0040755C |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Code function: 46_2_00406D85 | 46_2_00406D85 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C114B0 | 49_2_00007FF763C114B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C60490 | 49_2_00007FF763C60490 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C13190 | 49_2_00007FF763C13190 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C268F0 | 49_2_00007FF763C268F0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C14740 | 49_2_00007FF763C14740 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C04DD0 | 49_2_00007FF763C04DD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C464AC | 49_2_00007FF763C464AC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C3E4A0 | 49_2_00007FF763C3E4A0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C0C4D0 | 49_2_00007FF763C0C4D0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C5B44C | 49_2_00007FF763C5B44C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C043A0 | 49_2_00007FF763C043A0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C40360 | 49_2_00007FF763C40360 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C2F260 | 49_2_00007FF763C2F260 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C3E294 | 49_2_00007FF763C3E294 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C03220 | 49_2_00007FF763C03220 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C5A24C | 49_2_00007FF763C5A24C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C501C8 | 49_2_00007FF763C501C8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C491B8 | 49_2_00007FF763C491B8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C42130 | 49_2_00007FF763C42130 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C488F0 | 49_2_00007FF763C488F0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C3E8B0 | 49_2_00007FF763C3E8B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C248D0 | 49_2_00007FF763C248D0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C53860 | 49_2_00007FF763C53860 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C21790 | 49_2_00007FF763C21790 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C4D6AC | 49_2_00007FF763C4D6AC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C3E6A4 | 49_2_00007FF763C3E6A4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C5065C | 49_2_00007FF763C5065C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C535E4 | 49_2_00007FF763C535E4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C5A24C | 49_2_00007FF763C5A24C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C3F5C8 | 49_2_00007FF763C3F5C8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C49564 | 49_2_00007FF763C49564 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C4E544 | 49_2_00007FF763C4E544 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C50CDC | 49_2_00007FF763C50CDC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C51C70 | 49_2_00007FF763C51C70 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C02BF0 | 49_2_00007FF763C02BF0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C2DB70 | 49_2_00007FF763C2DB70 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C3EAB4 | 49_2_00007FF763C3EAB4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C2EAA0 | 49_2_00007FF763C2EAA0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C04A80 | 49_2_00007FF763C04A80 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C21A80 | 49_2_00007FF763C21A80 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C239B0 | 49_2_00007FF763C239B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C469B8 | 49_2_00007FF763C469B8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C5C95C | 49_2_00007FF763C5C95C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C07060 | 49_2_00007FF763C07060 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C3E090 | 49_2_00007FF763C3E090 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C20FE0 | 49_2_00007FF763C20FE0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C3FF5C | 49_2_00007FF763C3FF5C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C58EE4 | 49_2_00007FF763C58EE4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C57E1C | 49_2_00007FF763C57E1C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C5FDF4 | 49_2_00007FF763C5FDF4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C18DD0 | 49_2_00007FF763C18DD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C49D5C | 49_2_00007FF763C49D5C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Code function: 49_2_00007FF763C5DD94 | 49_2_00007FF763C5DD94 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B84740 | 52_2_00007FF694B84740 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BCF770 | 52_2_00007FF694BCF770 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B968B0 | 52_2_00007FF694B968B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B83190 | 52_2_00007FF694B83190 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B814B0 | 52_2_00007FF694B814B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B88DD0 | 52_2_00007FF694B88DD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BB1960 | 52_2_00007FF694BB1960 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BC2CE4 | 52_2_00007FF694BC2CE4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BC85E4 | 52_2_00007FF694BC85E4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BB9589 | 52_2_00007FF694BB9589 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BCA72C | 52_2_00007FF694BCA72C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B91790 | 52_2_00007FF694B91790 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BAF78C | 52_2_00007FF694BAF78C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BAD8C0 | 52_2_00007FF694BAD8C0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B948D0 | 52_2_00007FF694B948D0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BBF8C8 | 52_2_00007FF694BBF8C8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B73220 | 52_2_00007FF694B73220 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BB61E8 | 52_2_00007FF694BB61E8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B9E190 | 52_2_00007FF694B9E190 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BAE2E4 | 52_2_00007FF694BAE2E4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B9D260 | 52_2_00007FF694B9D260 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BC03DC | 52_2_00007FF694BC03DC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B743A0 | 52_2_00007FF694B743A0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BC1370 | 52_2_00007FF694BC1370 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BC751C | 52_2_00007FF694BC751C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B7C4D0 | 52_2_00007FF694B7C4D0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BAEDF8 | 52_2_00007FF694BAEDF8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B74DD0 | 52_2_00007FF694B74DD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BB8D94 | 52_2_00007FF694BB8D94 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BBFD5C | 52_2_00007FF694BBFD5C |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BBCD70 | 52_2_00007FF694BBCD70 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BADED4 | 52_2_00007FF694BADED4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B90FE0 | 52_2_00007FF694B90FE0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BC2F60 | 52_2_00007FF694BC2F60 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BB8120 | 52_2_00007FF694BB8120 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BCF0D4 | 52_2_00007FF694BCF0D4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BAE0E0 | 52_2_00007FF694BAE0E0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B77060 | 52_2_00007FF694B77060 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BCD074 | 52_2_00007FF694BCD074 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BB89E8 | 52_2_00007FF694BB89E8 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B939B0 | 52_2_00007FF694B939B0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BADAC4 | 52_2_00007FF694BADAC4 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B91A80 | 52_2_00007FF694B91A80 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B74A80 | 52_2_00007FF694B74A80 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694B72BF0 | 52_2_00007FF694B72BF0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BAFB90 | 52_2_00007FF694BAFB90 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BADCD0 | 52_2_00007FF694BADCD0 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BB5CDC | 52_2_00007FF694BB5CDC |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BBDC40 | 52_2_00007FF694BBDC40 |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Code function: 52_2_00007FF694BCBC3C | 52_2_00007FF694BCBC3C |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Code function: 66_2_0040755C | 66_2_0040755C |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Code function: 66_2_00406D85 | 66_2_00406D85 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750C68B0 | 72_2_00007FF6750C68B0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750B4740 | 72_2_00007FF6750B4740 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750FF770 | 72_2_00007FF6750FF770 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750B3190 | 72_2_00007FF6750B3190 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750B14B0 | 72_2_00007FF6750B14B0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750AC4D0 | 72_2_00007FF6750AC4D0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750B8DD0 | 72_2_00007FF6750B8DD0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750E1960 | 72_2_00007FF6750E1960 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750F2CE4 | 72_2_00007FF6750F2CE4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750FA72C | 72_2_00007FF6750FA72C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750E9589 | 72_2_00007FF6750E9589 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750F85E4 | 72_2_00007FF6750F85E4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750C48D0 | 72_2_00007FF6750C48D0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750EF8C8 | 72_2_00007FF6750EF8C8 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750DD8C0 | 72_2_00007FF6750DD8C0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750C1790 | 72_2_00007FF6750C1790 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750DF78C | 72_2_00007FF6750DF78C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750CD260 | 72_2_00007FF6750CD260 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750DE2E4 | 72_2_00007FF6750DE2E4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750CE190 | 72_2_00007FF6750CE190 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750E61E8 | 72_2_00007FF6750E61E8 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750A3220 | 72_2_00007FF6750A3220 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750F751C | 72_2_00007FF6750F751C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750F1370 | 72_2_00007FF6750F1370 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750A43A0 | 72_2_00007FF6750A43A0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750F03DC | 72_2_00007FF6750F03DC |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750DDED4 | 72_2_00007FF6750DDED4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750ECD70 | 72_2_00007FF6750ECD70 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750EFD5C | 72_2_00007FF6750EFD5C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750E8D94 | 72_2_00007FF6750E8D94 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750A4DD0 | 72_2_00007FF6750A4DD0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750DEDF8 | 72_2_00007FF6750DEDF8 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750FD074 | 72_2_00007FF6750FD074 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750A7060 | 72_2_00007FF6750A7060 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750FF0D4 | 72_2_00007FF6750FF0D4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750DE0E0 | 72_2_00007FF6750DE0E0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750E8120 | 72_2_00007FF6750E8120 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750F2F60 | 72_2_00007FF6750F2F60 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750C0FE0 | 72_2_00007FF6750C0FE0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750C1A80 | 72_2_00007FF6750C1A80 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750A4A80 | 72_2_00007FF6750A4A80 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750DDAC4 | 72_2_00007FF6750DDAC4 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750C39B0 | 72_2_00007FF6750C39B0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750E89E8 | 72_2_00007FF6750E89E8 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750EDC40 | 72_2_00007FF6750EDC40 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750FBC3C | 72_2_00007FF6750FBC3C |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750DDCD0 | 72_2_00007FF6750DDCD0 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750E5CDC | 72_2_00007FF6750E5CDC |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750DFB90 | 72_2_00007FF6750DFB90 |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Code function: 72_2_00007FF6750A2BF0 | 72_2_00007FF6750A2BF0 |
Source: unknown | Process created: C:\Users\user\Desktop\uu8v4UUzTU.exe "C:\Users\user\Desktop\uu8v4UUzTU.exe" | |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Process created: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp "C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp" /SL5="$10410,49640288,887296,C:\Users\user\Desktop\uu8v4UUzTU.exe" | |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z.bat" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\PSecWin\7z.exe "C:\Users\user\AppData\Roaming\PSecWin\7z.exe" x -aoa "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z" -p"fa073db961c" -o"C:\Users\user\AppData\Roaming\PSecWin\" | |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C del "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z.bat" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C del "SoundNight.7z" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "cmd" /C "C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-kill-parsec.vbs" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" control Parsec 200 | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /F /IM parsecd.exe | |
Source: C:\Windows\SysWOW64\taskkill.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-remove.vbs" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" stop Parsec | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" delete Parsec | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\firewall-remove.vbs" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=Parsec | |
Source: C:\Windows\SysWOW64\netsh.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=parsec.exe | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=parsecd.exe | |
Source: C:\Windows\SysWOW64\netsh.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\legacy-cleanup.vbs" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /delete /tn ParsecTeams /f | |
Source: C:\Windows\SysWOW64\schtasks.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-install.vbs" "C:\Program Files\Parsec\pservice.exe" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" create Parsec binPath= "\"C:\Program Files\Parsec\pservice.exe\"" start= auto type= interact type= own | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" start Parsec | |
Source: C:\Windows\SysWOW64\sc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Program Files\Parsec\pservice.exe "C:\Program Files\Parsec\pservice.exe" | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\firewall-add.vbs" "C:\Program Files\Parsec\parsecd.exe" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall add rule name=Parsec dir=in action=allow program="C:\Program Files\Parsec\parsecd.exe" enable=yes profile=public,private,domain | |
Source: C:\Windows\SysWOW64\netsh.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec\vusb\parsec-vud.exe" /S | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec\vusb\parsec-vud.exe "C:\Program Files\Parsec\vusb\parsec-vud.exe" /S | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe" --find-hwid --hardware-id VUSBA | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe "C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe" --find-hwid --hardware-id VUSBA | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Parsec Virtual USB Adapter Driver\vusbinstall.bat"" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --create-device-node --hardware-id Root\Parsec\VUSBA --class-name USB --class-guid "36fc9e60-c465-11cf-8056-444553540000" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --install-driver --inf-path ".\parsecvusba\parsecvusba.inf" | |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k DcomLaunch -p -s DeviceInstall | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{07ec11c3-0442-934e-b5ee-7c271dda5618}\parsecvusba.inf" "9" "464910f03" "000000000000015C" "WinSta0\Default" "0000000000000174" "208" "C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvusba" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "2" "201" "ROOT\USB\0000" "C:\Windows\System32\DriverStore\FileRepository\parsecvusba.inf_amd64_dae154cc0d6f64e9\parsecvusba.inf" "oem4.inf:*:*:0.2.8.0:Root\Parsec\VUSBA," "464910f03" "0000000000000170" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --inf-default-install --inf-path ".\parsecvirtualds\parsecvirtualds.inf" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{bea99733-6925-1c45-8b38-88de72198ece}\parsecvirtualds.inf" "9" "43799a85b" "000000000000015C" "WinSta0\Default" "00000000000000F4" "208" "C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvirtualds" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "8" "4" "C:\Windows\System32\DriverStore\FileRepository\parsecvirtualds.inf_amd64_dabce1c8ac909510\parsecvirtualds.inf" "0" "43799a85b" "00000000000000F4" "WinSta0\Default" | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process created: C:\Windows\System32\runonce.exe "C:\Windows\system32\runonce.exe" -r | |
Source: C:\Windows\System32\runonce.exe | Process created: C:\Windows\System32\grpconv.exe "C:\Windows\System32\grpconv.exe" -o | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "8" "4" "C:\Windows\System32\DriverStore\FileRepository\parsecvirtualds.inf_amd64_dabce1c8ac909510\parsecvirtualds.inf" "0" "4fea13f63" "000000000000018C" "WinSta0\Default" | |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec\vdd\parsec-vdd.exe" /S | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec\vdd\parsec-vdd.exe "C:\Program Files\Parsec\vdd\parsec-vdd.exe" /S | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: C:\Windows\SysWOW64\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" | |
Source: C:\Windows\SysWOW64\wevtutil.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wevtutil.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" /fromwow64 | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Parsec Virtual Display Driver\vddinstall.bat"" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --remove-device-node --hardware-id Root\Parsec\VDA --class-guid "4D36E968-E325-11CE-BFC1-08002BE10318" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --create-device-node --class-name Display --class-guid "4D36E968-E325-11CE-BFC1-08002BE10318" --hardware-id Root\Parsec\VDA | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --install-driver --inf-path ".\driver\mm.inf" | |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Process created: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp "C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp" /SL5="$10410,49640288,887296,C:\Users\user\Desktop\uu8v4UUzTU.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z.bat" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C del "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z.bat" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "CMD" /C del "SoundNight.7z" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process created: C:\Windows\SysWOW64\cmd.exe "cmd" /C "C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\PSecWin\7z.exe "C:\Users\user\AppData\Roaming\PSecWin\7z.exe" x -aoa "C:\Users\user\AppData\Roaming\PSecWin\SoundNight.7z" -p"fa073db961c" -o"C:\Users\user\AppData\Roaming\PSecWin\" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-kill-parsec.vbs" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-remove.vbs" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\firewall-remove.vbs" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\legacy-cleanup.vbs" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-install.vbs" "C:\Program Files\Parsec\pservice.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\firewall-add.vbs" "C:\Program Files\Parsec\parsecd.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\system32\wscript.exe" "C:\Program Files\Parsec\wscripts\service-kill-parsec.vbs" | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec\vdd\parsec-vdd.exe" /S | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process created: C:\Windows\SysWOW64\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" control Parsec 200 | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /F /IM parsecd.exe | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" stop Parsec | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" delete Parsec | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=Parsec | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=parsec.exe | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall delete rule name=parsecd.exe | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /delete /tn ParsecTeams /f | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" create Parsec binPath= "\"C:\Program Files\Parsec\pservice.exe\"" start= auto type= interact type= own | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\System32\sc.exe" start Parsec | |
Source: C:\Program Files\Parsec\pservice.exe | Process created: unknown unknown | |
Source: C:\Program Files\Parsec\pservice.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Program Files\Parsec\pservice.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\netsh.exe "C:\Windows\System32\netsh.exe" advfirewall firewall add rule name=Parsec dir=in action=allow program="C:\Program Files\Parsec\parsecd.exe" enable=yes profile=public,private,domain | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec\vusb\parsec-vud.exe "C:\Program Files\Parsec\vusb\parsec-vud.exe" /S | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe" --find-hwid --hardware-id VUSBA | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Parsec Virtual USB Adapter Driver\vusbinstall.bat"" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe "C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe" --find-hwid --hardware-id VUSBA | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --create-device-node --hardware-id Root\Parsec\VUSBA --class-name USB --class-guid "36fc9e60-c465-11cf-8056-444553540000" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --install-driver --inf-path ".\parsecvusba\parsecvusba.inf" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe nefconw.exe --inf-default-install --inf-path ".\parsecvirtualds\parsecvirtualds.inf" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{07ec11c3-0442-934e-b5ee-7c271dda5618}\parsecvusba.inf" "9" "464910f03" "000000000000015C" "WinSta0\Default" "0000000000000174" "208" "C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvusba" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "2" "201" "ROOT\USB\0000" "C:\Windows\System32\DriverStore\FileRepository\parsecvusba.inf_amd64_dae154cc0d6f64e9\parsecvusba.inf" "oem4.inf:*:*:0.2.8.0:Root\Parsec\VUSBA," "464910f03" "0000000000000170" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{bea99733-6925-1c45-8b38-88de72198ece}\parsecvirtualds.inf" "9" "43799a85b" "000000000000015C" "WinSta0\Default" "00000000000000F4" "208" "C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvirtualds" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "8" "4" "C:\Windows\System32\DriverStore\FileRepository\parsecvirtualds.inf_amd64_dabce1c8ac909510\parsecvirtualds.inf" "0" "43799a85b" "00000000000000F4" "WinSta0\Default" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "8" "4" "C:\Windows\System32\DriverStore\FileRepository\parsecvirtualds.inf_amd64_dabce1c8ac909510\parsecvirtualds.inf" "0" "4fea13f63" "000000000000018C" "WinSta0\Default" | |
Source: C:\Windows\System32\svchost.exe | Process created: unknown unknown | |
Source: C:\Windows\System32\svchost.exe | Process created: unknown unknown | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process created: C:\Windows\System32\runonce.exe "C:\Windows\system32\runonce.exe" -r | |
Source: C:\Windows\System32\runonce.exe | Process created: C:\Windows\System32\grpconv.exe "C:\Windows\System32\grpconv.exe" -o | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec\vdd\parsec-vdd.exe "C:\Program Files\Parsec\vdd\parsec-vdd.exe" /S | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: C:\Windows\SysWOW64\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Parsec Virtual Display Driver\vddinstall.bat"" | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process created: unknown unknown | |
Source: C:\Windows\SysWOW64\wevtutil.exe | Process created: C:\Windows\System32\wevtutil.exe wevtutil um "C:\Program Files\Parsec Virtual Display Driver\mm.man" /fromwow64 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --remove-device-node --hardware-id Root\Parsec\VDA --class-guid "4D36E968-E325-11CE-BFC1-08002BE10318" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --create-device-node --class-name Display --class-guid "4D36E968-E325-11CE-BFC1-08002BE10318" --hardware-id Root\Parsec\VDA | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe .\nefconw.exe --install-driver --inf-path ".\driver\mm.inf" | |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: winhttpcom.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ifmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasmontr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasapi32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mfc42u.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: authfwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcmonitor.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3cfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3api.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: onex.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ncrypt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappprxy.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ntasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: hnetmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netshell.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netsetupapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netiohlp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: httpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: activeds.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: polstore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshwfp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cabinet.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2pnetsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2p.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rpcnsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: whhelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlancfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlanapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wshelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wevtapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: peerdistsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wcmapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mobilenetworking.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprmsg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ifmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasmontr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasapi32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mfc42u.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: authfwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcmonitor.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3cfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3api.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: onex.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ncrypt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappprxy.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ntasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: hnetmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netshell.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netsetupapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netiohlp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: httpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: activeds.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: polstore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshwfp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cabinet.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2pnetsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2p.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rpcnsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: whhelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlancfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlanapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wshelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wevtapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: peerdistsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wcmapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mobilenetworking.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprmsg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ifmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasmontr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasapi32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rasman.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mfc42u.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: authfwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcmonitor.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3cfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dot3api.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: onex.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ncrypt.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: eappprxy.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ntasn1.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: fwcfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: hnetmon.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netshell.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netsetupapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: netiohlp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: httpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: activeds.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: polstore.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winipsec.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: adsldpc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: nshwfp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cabinet.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2pnetsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: p2p.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rpcnsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: whhelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlancfg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wlanapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wshelper.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wevtapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: peerdistsh.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wcmapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mobilenetworking.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: mprmsg.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\netsh.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: wtsapi32.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: msi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: sas.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: wldp.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: cryptnet.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: profapi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files\Parsec\pservice.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-6EGJL.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-MGUI8.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-NRIH7.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\verifier.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{07ec11c3-0442-934e-b5ee-7c271dda5618}\parsecvusba.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-CEDA5.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\7z.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Local\Temp\is-4VCD0.tmp\_isetup\_setup64.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-P56QD.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconc.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-86N5H.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | File created: C:\Windows\System32\DriverStore\Temp\{0d19f94d-19ef-cf46-8004-7828b47b053d}\parsecvirtualds.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\pservice.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\LockAppBroker.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\icuin.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\vusb\parsec-vud.exe | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | File created: C:\Windows\System32\DriverStore\Temp\{0d19f94d-19ef-cf46-8004-7828b47b053d}\SETE85A.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-1CLR0.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-H8DB6.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\kbdibm02.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\netlogon.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\UserDataAccessRes.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\shrpubw.exe (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{07ec11c3-0442-934e-b5ee-7c271dda5618}\SETDCF0.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\wlanext.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\dmcfgutils.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\TpmTool.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\gp548-win64-mingw.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-4SSD7.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\MCRecvSrc.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-PBFIO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-G4CQT.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\sscore.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{bea99733-6925-1c45-8b38-88de72198ece}\parsecvirtualds.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-QSA3H.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\MFWMAAEC.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-4HGOQ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-DQG3S.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-BUN5H.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\VscMgrPS.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\rdvgocl32.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{bea99733-6925-1c45-8b38-88de72198ece}\SETE77F.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-61CCU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-USCFG.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\SystemEventsBrokerClient.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\mcbuilder.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\VAN.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\Windows.UI.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-60VI8.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\TrustedSignalCredProv.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\xwreg.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | File created: C:\Windows\System32\DriverStore\Temp\{6f78882e-1a3d-dc43-867f-898abe828d58}\parsecvusba.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\IEAdvpack.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-ULHI4.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\Windows.ApplicationModel.ConversationalAgent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\unins000.exe (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Users\user\AppData\Local\Temp\nstD696.tmp\UserInfo.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-UI7FB.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\mfc140enu.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\networkhelper.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\wiashext.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\kbd101b.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\skel\parsecd-150-93b.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-8G60N.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-K5NEU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-HI4IL.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\socialapis.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\tapiui.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\dskquoui.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-HA8AR.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Users\user\AppData\Local\Temp\nsvA814.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\RdpSaUacHelper.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\teams.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-H42SM.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\KBDA3.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | File created: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-6DK0L.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvusba\parsecvusba.sys | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-O0GNS.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-1L3B3.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-N73AH.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-JRFAI.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\ws2help.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-2V0O4.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\7z.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-BK2QC.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-L6U16.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-PGRCJ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\runonce.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-IJKK2.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\WSClient.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Users\user\AppData\Local\Temp\nsvA814.tmp\nsDialogs.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Users\user\AppData\Local\Temp\nsvA814.tmp\ApplicationID.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\getuname.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Users\user\AppData\Local\Temp\nscF857.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-9HECR.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-39NTG.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\SyncInfrastructureps.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-MHHB2.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Program Files\Parsec Virtual Display Driver\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-BOVF1.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{d69aa289-d543-ea4a-a8fd-892bf2d05645}\SETFD68.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-I39R4.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-HCV6V.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\wups.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\7z.exe | File created: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Users\user\AppData\Local\Temp\nstD696.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\cryptdlg.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-G92OK.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | File created: C:\Users\user\AppData\Local\Temp\{d69aa289-d543-ea4a-a8fd-892bf2d05645}\mm.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvirtualds\parsecvirtualds.sys | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\netevent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-HQ9KB.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\MP43DECD.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-0LBKR.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\xpsservices.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\iesysprep.dll (copy) | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | File created: C:\Windows\System32\DriverStore\Temp\{6f78882e-1a3d-dc43-867f-898abe828d58}\SETDEC5.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-61DKO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-0BSQ7.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Users\user\AppData\Local\Temp\nscF857.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Program Files\Parsec\parsecd.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-PSU9B.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | File created: C:\Program Files\Parsec Virtual Display Driver\driver\mm.dll | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | File created: C:\Users\user\AppData\Local\Temp\nstD696.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\is-U20SU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | File created: C:\Users\user\AppData\Local\Temp\nsvA814.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | File created: C:\Users\user\AppData\Roaming\PSecWin\kbdarmty.dll (copy) | Jump to dropped file |
Source: C:\Users\user\Desktop\uu8v4UUzTU.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec\pservice.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec\pservice.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\netsh.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\runonce.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\grpconv.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\grpconv.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\grpconv.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\grpconv.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\drvinst.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-6EGJL.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-MGUI8.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-NRIH7.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\verifier.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{07ec11c3-0442-934e-b5ee-7c271dda5618}\parsecvusba.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\7z.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-CEDA5.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-4VCD0.tmp\_isetup\_setup64.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-P56QD.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-86N5H.tmp | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{0d19f94d-19ef-cf46-8004-7828b47b053d}\parsecvirtualds.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\LockAppBroker.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\icuin.dll (copy) | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{0d19f94d-19ef-cf46-8004-7828b47b053d}\SETE85A.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-1CLR0.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-H8DB6.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\kbdibm02.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\netlogon.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\UserDataAccessRes.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\shrpubw.exe (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{07ec11c3-0442-934e-b5ee-7c271dda5618}\SETDCF0.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\wlanext.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\dmcfgutils.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\gp548-win64-mingw.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\TpmTool.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\MCRecvSrc.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-4SSD7.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-PBFIO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-G4CQT.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\sscore.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{bea99733-6925-1c45-8b38-88de72198ece}\parsecvirtualds.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\MFWMAAEC.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-QSA3H.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-4HGOQ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Program Files\Parsec\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-DQG3S.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\VscMgrPS.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-BUN5H.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\rdvgocl32.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual USB Adapter Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{bea99733-6925-1c45-8b38-88de72198ece}\SETE77F.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-61CCU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-USCFG.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\SystemEventsBrokerClient.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\mcbuilder.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\VAN.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\Windows.UI.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\TrustedSignalCredProv.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\xwreg.dll (copy) | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{6f78882e-1a3d-dc43-867f-898abe828d58}\parsecvusba.sys (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\IEAdvpack.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-ULHI4.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\Windows.ApplicationModel.ConversationalAgent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\unins000.exe (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nstD696.tmp\UserInfo.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-UI7FB.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\mfc140enu.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\networkhelper.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\wiashext.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Program Files\Parsec\skel\parsecd-150-93b.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\kbd101b.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-8G60N.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual USB Adapter Driver\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-K5NEU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-HI4IL.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\socialapis.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\tapiui.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\dskquoui.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-HA8AR.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsvA814.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\RdpSaUacHelper.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Program Files\Parsec\teams.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-H42SM.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\KBDA3.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-6DK0L.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvusba\parsecvusba.sys | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-1L3B3.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-O0GNS.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-N73AH.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-JRFAI.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\ws2help.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-2V0O4.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-L6U16.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-BK2QC.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-PGRCJ.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\runonce.exe (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\WSClient.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-IJKK2.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsvA814.tmp\ApplicationID.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsvA814.tmp\nsDialogs.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\getuname.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nscF857.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-9HECR.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-39NTG.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\SyncInfrastructureps.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual Display Driver\uninstall.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-MHHB2.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-BOVF1.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{d69aa289-d543-ea4a-a8fd-892bf2d05645}\SETFD68.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-HCV6V.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-I39R4.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\wups.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nstD696.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\cryptdlg.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-G92OK.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec Virtual Display Driver\nefconw.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{d69aa289-d543-ea4a-a8fd-892bf2d05645}\mm.dll (copy) | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual USB Adapter Driver\parsecvirtualds\parsecvirtualds.sys | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\netevent.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-HQ9KB.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\MP43DECD.DLL (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-0LBKR.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\xpsservices.dll (copy) | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\iesysprep.dll (copy) | Jump to dropped file |
Source: C:\Windows\System32\drvinst.exe | Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{6f78882e-1a3d-dc43-867f-898abe828d58}\SETDEC5.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-61DKO.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-0BSQ7.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nscF857.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Program Files\Parsec\parsecd.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-PSU9B.tmp | Jump to dropped file |
Source: C:\Program Files\Parsec\vdd\parsec-vdd.exe | Dropped PE file which has not been started: C:\Program Files\Parsec Virtual Display Driver\driver\mm.dll | Jump to dropped file |
Source: C:\Program Files\Parsec\vusb\parsec-vud.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nstD696.tmp\nsExec.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\PSecWin\parsec-windows.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsvA814.tmp\System.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\is-U20SU.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-HDJTG.tmp\uu8v4UUzTU.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\PSecWin\kbdarmty.dll (copy) | Jump to dropped file |