Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002A6CA9 GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_002A6CA9 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002A60DD _wcscat,_wcscat,__wsplitpath,FindFirstFileW,DeleteFileW,_wcscpy,_wcscat,_wcscat,lstrcmpiW,DeleteFileW,MoveFileW,MoveFileW,CopyFileW,DeleteFileW,CopyFileW,FindNextFileW,FindClose,FindClose, |
0_2_002A60DD |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002A63F9 _wcscat,__wsplitpath,FindFirstFileW,_wcscpy,_wcscat,_wcscat,DeleteFileW,FindNextFileW,FindClose, |
0_2_002A63F9 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002AEB60 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
0_2_002AEB60 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002AF56F FindFirstFileW,FindClose, |
0_2_002AF56F |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002AF5FA FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
0_2_002AF5FA |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002B1B2F SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_002B1B2F |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002B1C8A SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_002B1C8A |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002B1F94 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
0_2_002B1F94 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AB6CA9 GetFileAttributesW,FindFirstFileW,FindClose, |
2_2_00AB6CA9 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AB60DD _wcscat,_wcscat,__wsplitpath,FindFirstFileW,DeleteFileW,_wcscpy,_wcscat,_wcscat,lstrcmpiW,DeleteFileW,MoveFileW,MoveFileW,CopyFileW,DeleteFileW,CopyFileW,FindNextFileW,FindClose,FindClose, |
2_2_00AB60DD |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AB63F9 _wcscat,__wsplitpath,FindFirstFileW,_wcscpy,_wcscat,_wcscat,DeleteFileW,FindNextFileW,FindClose, |
2_2_00AB63F9 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ABEB60 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
2_2_00ABEB60 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ABF5FA FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
2_2_00ABF5FA |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ABF56F FindFirstFileW,FindClose, |
2_2_00ABF56F |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AC1B2F SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
2_2_00AC1B2F |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AC1C8A SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
2_2_00AC1C8A |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AC1F94 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
2_2_00AC1F94 |
Source: RegSvcs.exe, 00000003.00000002.4511121854.00000000064D0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://r11.i.lenc |
Source: RegSvcs.exe, 00000003.00000002.4508762505.00000000033B3000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4508762505.0000000003208000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4511121854.00000000064D0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://r11.i.lencr.org/0# |
Source: RegSvcs.exe, 00000003.00000002.4508762505.00000000033B3000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4508762505.0000000003208000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4511121854.00000000064D0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://r11.o.lencr.org0# |
Source: RegSvcs.exe, 00000003.00000002.4508762505.00000000033B3000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4508762505.0000000003208000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4511121854.00000000064D0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://x1.c.lencr.org/0 |
Source: RegSvcs.exe, 00000003.00000002.4508762505.00000000033B3000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4508762505.0000000003208000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4511121854.00000000064D0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://x1.i.lencr.org/0 |
Source: RegSvcs.exe, 00000003.00000002.4508762505.00000000033B3000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4508762505.0000000003208000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://zqamcx.com |
Source: pteropod.exe, 00000002.00000002.2085926396.0000000004130000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.4507142862.0000000000402000.00000040.80000000.00040000.00000000.sdmp, pteropod.exe, 00000005.00000002.2225418640.0000000001030000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://account.dyn.com/ |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002CF7FF DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
0_2_002CF7FF |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ADF7FF DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
2_2_00ADF7FF |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: This is a third-party compiled AutoIt script. |
0_2_00263D19 |
Source: EKSTRE_1022.exe |
String found in binary or memory: This is a third-party compiled AutoIt script. |
|
Source: EKSTRE_1022.exe, 00000000.00000002.2063315668.000000000030E000.00000002.00000001.01000000.00000003.sdmp |
String found in binary or memory: This is a third-party compiled AutoIt script. |
memstr_a6a92aac-2 |
Source: EKSTRE_1022.exe, 00000000.00000002.2063315668.000000000030E000.00000002.00000001.01000000.00000003.sdmp |
String found in binary or memory: )SDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer |
memstr_2330edc1-9 |
Source: EKSTRE_1022.exe, 00000000.00000003.2062201560.0000000003A7D000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: This is a third-party compiled AutoIt script. |
memstr_712420f4-1 |
Source: EKSTRE_1022.exe, 00000000.00000003.2062201560.0000000003A7D000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: CSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer |
memstr_13915c03-7 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: This is a third-party compiled AutoIt script. |
2_2_00A73D19 |
Source: pteropod.exe |
String found in binary or memory: This is a third-party compiled AutoIt script. |
|
Source: pteropod.exe, 00000002.00000002.2084777705.0000000000B1E000.00000002.00000001.01000000.00000004.sdmp |
String found in binary or memory: This is a third-party compiled AutoIt script. |
memstr_633a2f05-c |
Source: pteropod.exe, 00000002.00000002.2084777705.0000000000B1E000.00000002.00000001.01000000.00000004.sdmp |
String found in binary or memory: SDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer |
memstr_28499bdd-a |
Source: pteropod.exe, 00000005.00000000.2198511784.0000000000B1E000.00000002.00000001.01000000.00000004.sdmp |
String found in binary or memory: This is a third-party compiled AutoIt script. |
memstr_3f5ca10e-1 |
Source: pteropod.exe, 00000005.00000000.2198511784.0000000000B1E000.00000002.00000001.01000000.00000004.sdmp |
String found in binary or memory: SDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer |
memstr_3a26fbca-8 |
Source: EKSTRE_1022.exe |
String found in binary or memory: This is a third-party compiled AutoIt script. |
memstr_6b161366-0 |
Source: EKSTRE_1022.exe |
String found in binary or memory: CSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer |
memstr_58722d25-f |
Source: pteropod.exe.0.dr |
String found in binary or memory: This is a third-party compiled AutoIt script. |
memstr_dae2da6e-0 |
Source: pteropod.exe.0.dr |
String found in binary or memory: CSDSOFTWARE\Classes\\CLSID\\\IPC$This is a third-party compiled AutoIt script."runasError allocating memory.SeAssignPrimaryTokenPrivilegeSeIncreaseQuotaPrivilegeSeBackupPrivilegeSeRestorePrivilegewinsta0defaultwinsta0\defaultComboBoxListBox|SHELLDLL_DefViewlargeiconsdetailssmalliconslistCLASSCLASSNNREGEXPCLASSIDNAMEXYWHINSTANCETEXT%s%u%s%dLAST[LASTACTIVE[ACTIVEHANDLE=[HANDLE:REGEXP=[REGEXPTITLE:CLASSNAME=[CLASS:ALL[ALL]HANDLEREGEXPTITLETITLEThumbnailClassAutoIt3GUIContainer |
memstr_e655a4dc-6 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0028B043 |
0_2_0028B043 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_00273200 |
0_2_00273200 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_00273B70 |
0_2_00273B70 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0029410F |
0_2_0029410F |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002802A4 |
0_2_002802A4 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0026E3B0 |
0_2_0026E3B0 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0029038E |
0_2_0029038E |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0029467F |
0_2_0029467F |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002806D9 |
0_2_002806D9 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002CAACE |
0_2_002CAACE |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_00294BEF |
0_2_00294BEF |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0028CCC1 |
0_2_0028CCC1 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_00266F07 |
0_2_00266F07 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0026AF50 |
0_2_0026AF50 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0027B11F |
0_2_0027B11F |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002C31BC |
0_2_002C31BC |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0028D1B9 |
0_2_0028D1B9 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0028123A |
0_2_0028123A |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0029724D |
0_2_0029724D |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002693F0 |
0_2_002693F0 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002A13CA |
0_2_002A13CA |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0027F563 |
0_2_0027F563 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002AB6CC |
0_2_002AB6CC |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002696C0 |
0_2_002696C0 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002677B0 |
0_2_002677B0 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002CF7FF |
0_2_002CF7FF |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002979C9 |
0_2_002979C9 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0027FA57 |
0_2_0027FA57 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_00269B60 |
0_2_00269B60 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_00267D19 |
0_2_00267D19 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0027FE6F |
0_2_0027FE6F |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_00289ED0 |
0_2_00289ED0 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_00267FA3 |
0_2_00267FA3 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_01351148 |
0_2_01351148 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A9B043 |
2_2_00A9B043 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A83200 |
2_2_00A83200 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A83B70 |
2_2_00A83B70 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AA410F |
2_2_00AA410F |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A902A4 |
2_2_00A902A4 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A7E3B0 |
2_2_00A7E3B0 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AA038E |
2_2_00AA038E |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A906D9 |
2_2_00A906D9 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AA467F |
2_2_00AA467F |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ADAACE |
2_2_00ADAACE |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AA4BEF |
2_2_00AA4BEF |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A9CCC1 |
2_2_00A9CCC1 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A76F07 |
2_2_00A76F07 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A7AF50 |
2_2_00A7AF50 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A9D1B9 |
2_2_00A9D1B9 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AD31BC |
2_2_00AD31BC |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A8B11F |
2_2_00A8B11F |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A9123A |
2_2_00A9123A |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AA724D |
2_2_00AA724D |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A793F0 |
2_2_00A793F0 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AB13CA |
2_2_00AB13CA |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A8F563 |
2_2_00A8F563 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ABB6CC |
2_2_00ABB6CC |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A796C0 |
2_2_00A796C0 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A777B0 |
2_2_00A777B0 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ADF7FF |
2_2_00ADF7FF |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AA79C9 |
2_2_00AA79C9 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A8FA57 |
2_2_00A8FA57 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A79B60 |
2_2_00A79B60 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A77D19 |
2_2_00A77D19 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A99ED0 |
2_2_00A99ED0 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A8FE6F |
2_2_00A8FE6F |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A77FA3 |
2_2_00A77FA3 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_01A544F0 |
2_2_01A544F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_013641B8 |
3_2_013641B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_01369B40 |
3_2_01369B40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_01364A88 |
3_2_01364A88 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_0136CDC0 |
3_2_0136CDC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_01363E70 |
3_2_01363E70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_0136F4B9 |
3_2_0136F4B9 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 5_2_0132D2B8 |
5_2_0132D2B8 |
Source: 5.2.pteropod.exe.1030000.1.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 3.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 5.2.pteropod.exe.1030000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.pteropod.exe.4130000.1.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 2.2.pteropod.exe.4130000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000002.00000002.2085926396.0000000004130000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000005.00000002.2225418640.0000000001030000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mlang.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002C8111 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
0_2_002C8111 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_0027EB42 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
0_2_0027EB42 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AD8111 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
2_2_00AD8111 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00A8EB42 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
2_2_00A8EB42 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002A6CA9 GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_002A6CA9 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002A60DD _wcscat,_wcscat,__wsplitpath,FindFirstFileW,DeleteFileW,_wcscpy,_wcscat,_wcscat,lstrcmpiW,DeleteFileW,MoveFileW,MoveFileW,CopyFileW,DeleteFileW,CopyFileW,FindNextFileW,FindClose,FindClose, |
0_2_002A60DD |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002A63F9 _wcscat,__wsplitpath,FindFirstFileW,_wcscpy,_wcscat,_wcscat,DeleteFileW,FindNextFileW,FindClose, |
0_2_002A63F9 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002AEB60 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
0_2_002AEB60 |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002AF56F FindFirstFileW,FindClose, |
0_2_002AF56F |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002AF5FA FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
0_2_002AF5FA |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002B1B2F SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_002B1B2F |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002B1C8A SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_002B1C8A |
Source: C:\Users\user\Desktop\EKSTRE_1022.exe |
Code function: 0_2_002B1F94 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
0_2_002B1F94 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AB6CA9 GetFileAttributesW,FindFirstFileW,FindClose, |
2_2_00AB6CA9 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AB60DD _wcscat,_wcscat,__wsplitpath,FindFirstFileW,DeleteFileW,_wcscpy,_wcscat,_wcscat,lstrcmpiW,DeleteFileW,MoveFileW,MoveFileW,CopyFileW,DeleteFileW,CopyFileW,FindNextFileW,FindClose,FindClose, |
2_2_00AB60DD |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AB63F9 _wcscat,__wsplitpath,FindFirstFileW,_wcscpy,_wcscat,_wcscat,DeleteFileW,FindNextFileW,FindClose, |
2_2_00AB63F9 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ABEB60 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
2_2_00ABEB60 |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ABF5FA FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
2_2_00ABF5FA |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00ABF56F FindFirstFileW,FindClose, |
2_2_00ABF56F |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AC1B2F SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
2_2_00AC1B2F |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AC1C8A SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
2_2_00AC1C8A |
Source: C:\Users\user\AppData\Local\ageless\pteropod.exe |
Code function: 2_2_00AC1F94 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
2_2_00AC1F94 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99891 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99674 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99516 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99398 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99297 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99187 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99078 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98969 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98860 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98735 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98610 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98485 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98360 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98235 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98110 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97985 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97860 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97735 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97610 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97485 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97360 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97235 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97110 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96964 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96721 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96594 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96485 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96369 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96264 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96157 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96032 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95907 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95782 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95657 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95532 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95398 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95297 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95188 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95063 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 94938 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 94813 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 94688 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 94579 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 94454 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 94330 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 94105 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 93988 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 93875 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 93766 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 93657 |
Jump to behavior |