Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD325B4 | 0_2_00007FFACCD325B4 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD3AD75 | 0_2_00007FFACCD3AD75 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD3FD1C | 0_2_00007FFACCD3FD1C |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD37536 | 0_2_00007FFACCD37536 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD3D28E | 0_2_00007FFACCD3D28E |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD38A6C | 0_2_00007FFACCD38A6C |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD31679 | 0_2_00007FFACCD31679 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD315F0 | 0_2_00007FFACCD315F0 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD382E2 | 0_2_00007FFACCD382E2 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD39048 | 0_2_00007FFACCD39048 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD31828 | 0_2_00007FFACCD31828 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD3C005 | 0_2_00007FFACCD3C005 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD31408 | 0_2_00007FFACCD31408 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD33810 | 0_2_00007FFACCD33810 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD31540 | 0_2_00007FFACCD31540 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD3AE83 | 0_2_00007FFACCD3AE83 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD337B9 | 0_2_00007FFACCD337B9 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD31308 | 0_2_00007FFACCD31308 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD3C30D | 0_2_00007FFACCD3C30D |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD31310 | 0_2_00007FFACCD31310 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD3F4A0 | 0_2_00007FFACCD3F4A0 |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD4043E | 0_2_00007FFACCD4043E |
Source: C:\Users\user\Desktop\exe006.exe | Code function: 0_2_00007FFACCD403F0 | 0_2_00007FFACCD403F0 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD225B4 | 12_2_00007FFACCD225B4 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD27536 | 12_2_00007FFACCD27536 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD2D28E | 12_2_00007FFACCD2D28E |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD28A6C | 12_2_00007FFACCD28A6C |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD2EE70 | 12_2_00007FFACCD2EE70 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD21679 | 12_2_00007FFACCD21679 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD2BA20 | 12_2_00007FFACCD2BA20 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD2AE30 | 12_2_00007FFACCD2AE30 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD215F0 | 12_2_00007FFACCD215F0 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD2E7A5 | 12_2_00007FFACCD2E7A5 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD282E2 | 12_2_00007FFACCD282E2 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD29048 | 12_2_00007FFACCD29048 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD23810 | 12_2_00007FFACCD23810 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD2BFF5 | 12_2_00007FFACCD2BFF5 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD2E540 | 12_2_00007FFACCD2E540 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD237B9 | 12_2_00007FFACCD237B9 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD21308 | 12_2_00007FFACCD21308 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD2C30D | 12_2_00007FFACCD2C30D |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD21310 | 12_2_00007FFACCD21310 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 12_2_00007FFACCD31741 | 12_2_00007FFACCD31741 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD0EEDA | 22_2_00007FFACCD0EEDA |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD0E4C4 | 22_2_00007FFACCD0E4C4 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD0AEA0 | 22_2_00007FFACCD0AEA0 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD0D28E | 22_2_00007FFACCD0D28E |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD0C055 | 22_2_00007FFACCD0C055 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD0E855 | 22_2_00007FFACCD0E855 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD0BA20 | 22_2_00007FFACCD0BA20 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD0C30D | 22_2_00007FFACCD0C30D |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD025B4 | 22_2_00007FFACCD025B4 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD07536 | 22_2_00007FFACCD07536 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD082E2 | 22_2_00007FFACCD082E2 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD08A6C | 22_2_00007FFACCD08A6C |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD01670 | 22_2_00007FFACCD01670 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD037B9 | 22_2_00007FFACCD037B9 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 22_2_00007FFACCD01308 | 22_2_00007FFACCD01308 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD0BFB0 | 26_2_00007FFACCD0BFB0 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD025B4 | 26_2_00007FFACCD025B4 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD0AD85 | 26_2_00007FFACCD0AD85 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD07536 | 26_2_00007FFACCD07536 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD082E2 | 26_2_00007FFACCD082E2 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD08A6C | 26_2_00007FFACCD08A6C |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD09048 | 26_2_00007FFACCD09048 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD0E648 | 26_2_00007FFACCD0E648 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD0BA20 | 26_2_00007FFACCD0BA20 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD03810 | 26_2_00007FFACCD03810 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD015F0 | 26_2_00007FFACCD015F0 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD037B9 | 26_2_00007FFACCD037B9 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD01308 | 26_2_00007FFACCD01308 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 26_2_00007FFACCD0C30D | 26_2_00007FFACCD0C30D |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD2EEDA | 36_2_00007FFACCD2EEDA |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD2E4C4 | 36_2_00007FFACCD2E4C4 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD2AEA0 | 36_2_00007FFACCD2AEA0 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD2D28E | 36_2_00007FFACCD2D28E |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD2C055 | 36_2_00007FFACCD2C055 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD2E855 | 36_2_00007FFACCD2E855 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD2BA20 | 36_2_00007FFACCD2BA20 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD2C30D | 36_2_00007FFACCD2C30D |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD225B4 | 36_2_00007FFACCD225B4 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD27536 | 36_2_00007FFACCD27536 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD282E2 | 36_2_00007FFACCD282E2 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD28A6C | 36_2_00007FFACCD28A6C |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD21670 | 36_2_00007FFACCD21670 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD21308 | 36_2_00007FFACCD21308 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 36_2_00007FFACCD23800 | 36_2_00007FFACCD23800 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD1BFB0 | 46_2_00007FFACCD1BFB0 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD125B4 | 46_2_00007FFACCD125B4 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD1AD85 | 46_2_00007FFACCD1AD85 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD17536 | 46_2_00007FFACCD17536 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD182E2 | 46_2_00007FFACCD182E2 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD1E4C4 | 46_2_00007FFACCD1E4C4 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD18A6C | 46_2_00007FFACCD18A6C |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD19048 | 46_2_00007FFACCD19048 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD13810 | 46_2_00007FFACCD13810 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD115F0 | 46_2_00007FFACCD115F0 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD11308 | 46_2_00007FFACCD11308 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD1C30D | 46_2_00007FFACCD1C30D |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD17039 | 46_2_00007FFACCD17039 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD13800 | 46_2_00007FFACCD13800 |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Code function: 46_2_00007FFACCD1E5DD | 46_2_00007FFACCD1E5DD |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD1EEDA | 53_2_00007FFACCD1EEDA |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD1AEA0 | 53_2_00007FFACCD1AEA0 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD1D28E | 53_2_00007FFACCD1D28E |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD1E85D | 53_2_00007FFACCD1E85D |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD1C055 | 53_2_00007FFACCD1C055 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD1C30D | 53_2_00007FFACCD1C30D |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD1E620 | 53_2_00007FFACCD1E620 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD175B3 | 53_2_00007FFACCD175B3 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD125B4 | 53_2_00007FFACCD125B4 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD18363 | 53_2_00007FFACCD18363 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD18A6C | 53_2_00007FFACCD18A6C |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD11670 | 53_2_00007FFACCD11670 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD11308 | 53_2_00007FFACCD11308 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Code function: 53_2_00007FFACCD13800 | 53_2_00007FFACCD13800 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5812:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3240:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4800:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6908:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6876:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1408:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7908:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5432:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4644:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1944:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4924:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:820:304:WilStaging_02 |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:684:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4736:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1944:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5348:304:WilStaging_02 |
Source: C:\Users\user\Desktop\exe006.exe | Mutant created: \Sessions\1\BaseNamedObjects\Sheet_logcmaxafpeqogwwv |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4644:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4800:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2424:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3244:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5812:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6284:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3420:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1408:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7908:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4952:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7464:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4952:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:916:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3420:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7872:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2556:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2556:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4736:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6284:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5348:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5432:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8040:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4604:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1116:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:332:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1116:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4704:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6908:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5088:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7872:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4604:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:332:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:684:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7464:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3368:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4704:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:820:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:916:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5244:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6876:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5088:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2424:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3240:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3244:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3368:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5244:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4924:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8040:120:WilError_03 |
Source: unknown | Process created: C:\Users\user\Desktop\exe006.exe "C:\Users\user\Desktop\exe006.exe" | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\wbem\WmiPrvSE.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Inkscape Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Inkscape Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo 5 /tn "Paint.NET Update" /tr "C:\Users\user\AppData\Roaming\xdwdInkscape.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo 5 /tn "Paint.NET Update" /tr "C:\Users\user\AppData\Roaming\xdwdInkscape.exe" /RL HIGHEST | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\xdwdInkscape.exe C:\Users\user\AppData\Roaming\xdwdInkscape.exe | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\xdwdInkscape.exe "C:\Users\user\AppData\Roaming\xdwdInkscape.exe" | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: unknown | Process created: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\xdwdInkscape.exe "C:\Users\user\AppData\Roaming\xdwdInkscape.exe" | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: unknown | Process created: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\schtasks.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\schtasks.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\schtasks.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Inkscape Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo 5 /tn "Paint.NET Update" /tr "C:\Users\user\AppData\Roaming\xdwdInkscape.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Inkscape Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo 5 /tn "Paint.NET Update" /tr "C:\Users\user\AppData\Roaming\xdwdInkscape.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Inkscape Upgrade" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: devenum.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: thumbcache.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: thumbcache.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: photometadatahandler.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: mfsrcsnk.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: mfplat.dll | Jump to behavior |
Source: C:\Windows\System32\dllhost.exe | Section loaded: rtworkq.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: devenum.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: twext.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: cscui.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: workfoldersshell.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: windows.fileexplorer.common.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: shacct.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: idstore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wlidprov.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: provsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: usermgrcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: usermgrproxy.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: acppage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: windows.staterepositorycore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: devenum.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: devenum.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\System32\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: edgegdi.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: wbemcomn.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: sxs.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: devenum.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: devobj.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: msdmo.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: edgegdi.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wbemcomn.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: sxs.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: devenum.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: devobj.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: msdmo.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\System32\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: edgegdi.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: wbemcomn.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: sxs.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: devenum.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: devobj.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: msdmo.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Section loaded: secur32.dll | |
Source: exe006.exe, qsdQmnOoVClj.cs | High entropy of concatenated method names: 'BBZkvyAPXc', 'RGrLJYfTz', 'DQVngFtARgbT', 'JufAgWuMTPRzf', 'DewXSjoxkExPsGP', 'vkxYhQdY', 'wERkAEnBKqVUIJk', 'MJbCReoxMUgBGN', 'BXZVeXNjAKOiQ', 'lmbNfVHCWhSQTXg' |
Source: exe006.exe, srWopDvYJJOjOnI.cs | High entropy of concatenated method names: 'uimypVWDtvrBM', 'qKQlldlrakIFge', 'ncjdWsAM', 'JWUTutMuLQTESd', 'eADICpjo', 'yGTHXqAqycbOJS', 'gYOuQKBUyhyWpsK', 'aibUnaEWUPdGqCo', 'hGbdbpXiwmV', 'ZULxneAghxJG' |
Source: exe006.exe, XrMMxtush.cs | High entropy of concatenated method names: 'dwVYqImEIhTDpP', 'KpXdLLHt', 'lXvRBCdIIcKswUU', 'lrBSqUBwImDWO', 'eWCVmSNUCGD', 'uMFLOUDsa', 'GbJRVyJOyHt', 'yopbiBXQouOfZp', 'wYjTVuJQbLVwPL', 'HwRHORVmmBUKgL' |
Source: exe006.exe, hBbQNQJD.cs | High entropy of concatenated method names: '_003CStart_003Eb__1_0', '_003CUninstall_003Eb__2_0', '_003CLoopInstall_003Eb__7_0', '_003CStartAsBypass_003Eb__10_0', 'KurqwgagxNy', 'CGaKKTHmdelMnLw', 'KQHVXscSdXLnZZ', 'tOBfuBGDwBQuf', 'fDlkjWhGc', 'KdIgnIUNEurx' |
Source: exe006.exe, frZPmBqczWzjyX.cs | High entropy of concatenated method names: '_003CScreenShot_003Eb__16_0', 'PxZzaRzv', 'RLamSbrSfiZhgX', 'QyWViugRl', 'JKpSZYfvl', 'baDKXegDQyTjaSi', 'ueNsltpZIQCA', 'JtmuZfqu', 'xDOcBntaj', 'jxdBitMhkdC' |
Source: exe006.exe, xUOyeShR.cs | High entropy of concatenated method names: 'DbVGEuzydnVE', 'uOaMwvWnTrZWN', 'qTftniuklHFU', 'RQalZANZAYR', 'mvojkvkqUIe', 'uhWqKcTHbZEWtFA', 'AAqvNXAnFAB', 'UdAImcqre', 'PXEKuNqRqev', 'qTSjkXhikJ' |
Source: exe006.exe, JLFJyQOxrUocHMR.cs | High entropy of concatenated method names: 'BesGKPjZklF', 'JsABkLHTIdxtom', 'GvZiLNwEQ', 'jmubgZNKYnzUm', 'wEyPXgzSYDcdKC', 'cMnjUAYNrbEjiPy', 'mJimHPggk', 'ROqyCPLPvbMlR', 'XqGoTwQCZrqUbP', 'NfGzniKXtZpYTU' |
Source: exe006.exe, iKlbjEWF.cs | High entropy of concatenated method names: 'oREAjAFwuPLSSMF', 'ZwcsRkGQwxz', 'sNpajGqQZIzlfL', 'COkQxfGJHtMg', 'LnEmBPEh', 'kiMWpvRxqNGF', 'BMgBKmDh', 'WZmEmENkPGxbe', 'EbpKsKCz', 'yHlsFzESdtEL' |
Source: exe006.exe, JPENuWcmsm.cs | High entropy of concatenated method names: 'rciNtryioDyxr', 'ydwqwguTCB', 'XYPTHQscVbsxXh', 'GNLMLRNyvtfw', 'FnXZhXWTiPhnGVW', 'GfYJWahHqpYKZT', 'bUwWhDSPAKG', 'yeYEwqKpNGm', 'fFQjsyLtOpF', 'KyokoQYyPCi' |
Source: exe006.exe, YNztyhHeKkmQHuK.cs | High entropy of concatenated method names: 'QOdKPQKDllsyRlV', 'bXonLTWHVeoW', 'IulNJGRguhID', 'HMoJMZOFokGXlwr', 'pkcnccrHkHe', 'AhqgjPLK', 'LSPHUTKeqY', 'ZKEwfPTfV', 'ZEuJFHuanVkhD', 'SNfIJgctjVfq' |
Source: exe006.exe, aBntsXuMmjIFHIP.cs | High entropy of concatenated method names: 'tXkUzvNYRAowV', 'lfagTZlKYVLotM', 'boNLdNsydu', 'nObrjxqtycfb', 'pyjyOILCAKpMbl', 'fsgwlpmWihmOxz', 'kwNYWeeukV', 'bnElfHMyNGwjp', 'DcARcuNCmZtyCOO', 'xwbCNyRw' |
Source: exe006.exe, bwAaLGyc.cs | High entropy of concatenated method names: 'jkaiIzFGVBHqhz', 'XbXawtov', 'KukIziUBcb', 'sjdmnGafMhMt', 'vDjiXfvupHYNPwG', 'gGOGVMoxlnpTJ', 'lyAnMwymdwgjD', 'FYXKTsfaynbi', 'lxkpckHVaN', 'kJnudRamJLsM' |
Source: exe006.exe, OWTOYIZIJyNpKGH.cs | High entropy of concatenated method names: 'LnHAELgikUQp', 'NhgCvHdVYixGPY', 'vgNftLwb', 'zqDpleEs', 'PvQhnOydGnEJt', 'mdmDHkwhQFaCFE', 'kteFWzcnOtyhQF', 'XwGAQMyaw', 'nieKGkJto', 'taDWpJpYKIC' |
Source: exe006.exe, JhLaGgFnnm.cs | High entropy of concatenated method names: 'BBjJuiKHFhm', 'nWnwFzteBFN', 'RaRCAxpwyRa', 'MzItENDlW', 'YDTkznuIUv', 'PsTRHGIsqVWwbk', 'qzZoCbxD', 'NjPxCBqx', 'XwHpbxGutgrB', 'rAtxujftM' |
Source: exe006.exe, IDIkloTpeDEKz.cs | High entropy of concatenated method names: 'RtTbNdmgGNTiJ', 'BLozuJcwWEM', 'OoFXWLLvM', 'XvFCAcwvR', 'etnSPEPp', 'UXOOCPxb', 'rIWONsosurJzz', 'nJhVBmIRvWpr', 'IhDnCBNDIhQgu', 'WKXfGVvaFVuw' |
Source: exe006.exe, pGsFKCRggcflWBU.cs | High entropy of concatenated method names: 'csbRpcNXkOoIzfw', 'uIxOoEjoAXb', 'DluUoDhMLzH', 'tUUwOJgBgJ', 'NEFJXJnQSBtUzU', 'UwxjJuBjVUj', 'arqZntugQitKCY', 'pMAzUcupkDwAx', 'UkpnVNYbb', 'aFnDlCnh' |
Source: exe006.exe, ABjlTGoWuueDjB.cs | High entropy of concatenated method names: 'JYOTNpHAD', 'reVCOQvt', 'SWrZvqwwII', 'XcphJzhmw', 'tBgkbcSU', 'djJSinSyTcQt', 'rrdPoosPiIxQYUK', 'TOecdecNJHurAO', 'fHuJoGMne', 'QvaMCJSHJzNm' |
Source: exe006.exe, jtMfOsvbzLJS.cs | High entropy of concatenated method names: 'OXvquBcTtRB', 'PetEeZGgzc', 'ZMJZQzqsHMAFC', 'jeZuIpcLQzOB', 'VmCmXloVdlc', 'TDYuBPZqe', 'vhlrnGOvJLOdUGE', 'cTOFFsxhomDQ', 'koKsaqVAfy', 'GibQyqjRpamFc' |
Source: exe006.exe, TfVjXoNYBK.cs | High entropy of concatenated method names: 'fFjUeBGQwOKqkzc', 'OrEmJMyvye', 'MAZQLNineBcsV', 'QPCJoljv', 'zhxYlSHoVzR', 'PXxycCLxRlyijtw', 'lJtzQfajOpwUXNH', 'EHAsFLLiXxENiP', 'sWLCLGSekxOknF', 'aEeFecsEqayKbT' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, qsdQmnOoVClj.cs | High entropy of concatenated method names: 'BBZkvyAPXc', 'RGrLJYfTz', 'DQVngFtARgbT', 'JufAgWuMTPRzf', 'DewXSjoxkExPsGP', 'vkxYhQdY', 'wERkAEnBKqVUIJk', 'MJbCReoxMUgBGN', 'BXZVeXNjAKOiQ', 'lmbNfVHCWhSQTXg' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, srWopDvYJJOjOnI.cs | High entropy of concatenated method names: 'uimypVWDtvrBM', 'qKQlldlrakIFge', 'ncjdWsAM', 'JWUTutMuLQTESd', 'eADICpjo', 'yGTHXqAqycbOJS', 'gYOuQKBUyhyWpsK', 'aibUnaEWUPdGqCo', 'hGbdbpXiwmV', 'ZULxneAghxJG' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, XrMMxtush.cs | High entropy of concatenated method names: 'dwVYqImEIhTDpP', 'KpXdLLHt', 'lXvRBCdIIcKswUU', 'lrBSqUBwImDWO', 'eWCVmSNUCGD', 'uMFLOUDsa', 'GbJRVyJOyHt', 'yopbiBXQouOfZp', 'wYjTVuJQbLVwPL', 'HwRHORVmmBUKgL' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, hBbQNQJD.cs | High entropy of concatenated method names: '_003CStart_003Eb__1_0', '_003CUninstall_003Eb__2_0', '_003CLoopInstall_003Eb__7_0', '_003CStartAsBypass_003Eb__10_0', 'KurqwgagxNy', 'CGaKKTHmdelMnLw', 'KQHVXscSdXLnZZ', 'tOBfuBGDwBQuf', 'fDlkjWhGc', 'KdIgnIUNEurx' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, frZPmBqczWzjyX.cs | High entropy of concatenated method names: '_003CScreenShot_003Eb__16_0', 'PxZzaRzv', 'RLamSbrSfiZhgX', 'QyWViugRl', 'JKpSZYfvl', 'baDKXegDQyTjaSi', 'ueNsltpZIQCA', 'JtmuZfqu', 'xDOcBntaj', 'jxdBitMhkdC' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, xUOyeShR.cs | High entropy of concatenated method names: 'DbVGEuzydnVE', 'uOaMwvWnTrZWN', 'qTftniuklHFU', 'RQalZANZAYR', 'mvojkvkqUIe', 'uhWqKcTHbZEWtFA', 'AAqvNXAnFAB', 'UdAImcqre', 'PXEKuNqRqev', 'qTSjkXhikJ' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, JLFJyQOxrUocHMR.cs | High entropy of concatenated method names: 'BesGKPjZklF', 'JsABkLHTIdxtom', 'GvZiLNwEQ', 'jmubgZNKYnzUm', 'wEyPXgzSYDcdKC', 'cMnjUAYNrbEjiPy', 'mJimHPggk', 'ROqyCPLPvbMlR', 'XqGoTwQCZrqUbP', 'NfGzniKXtZpYTU' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, iKlbjEWF.cs | High entropy of concatenated method names: 'oREAjAFwuPLSSMF', 'ZwcsRkGQwxz', 'sNpajGqQZIzlfL', 'COkQxfGJHtMg', 'LnEmBPEh', 'kiMWpvRxqNGF', 'BMgBKmDh', 'WZmEmENkPGxbe', 'EbpKsKCz', 'yHlsFzESdtEL' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, JPENuWcmsm.cs | High entropy of concatenated method names: 'rciNtryioDyxr', 'ydwqwguTCB', 'XYPTHQscVbsxXh', 'GNLMLRNyvtfw', 'FnXZhXWTiPhnGVW', 'GfYJWahHqpYKZT', 'bUwWhDSPAKG', 'yeYEwqKpNGm', 'fFQjsyLtOpF', 'KyokoQYyPCi' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, YNztyhHeKkmQHuK.cs | High entropy of concatenated method names: 'QOdKPQKDllsyRlV', 'bXonLTWHVeoW', 'IulNJGRguhID', 'HMoJMZOFokGXlwr', 'pkcnccrHkHe', 'AhqgjPLK', 'LSPHUTKeqY', 'ZKEwfPTfV', 'ZEuJFHuanVkhD', 'SNfIJgctjVfq' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, aBntsXuMmjIFHIP.cs | High entropy of concatenated method names: 'tXkUzvNYRAowV', 'lfagTZlKYVLotM', 'boNLdNsydu', 'nObrjxqtycfb', 'pyjyOILCAKpMbl', 'fsgwlpmWihmOxz', 'kwNYWeeukV', 'bnElfHMyNGwjp', 'DcARcuNCmZtyCOO', 'xwbCNyRw' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, bwAaLGyc.cs | High entropy of concatenated method names: 'jkaiIzFGVBHqhz', 'XbXawtov', 'KukIziUBcb', 'sjdmnGafMhMt', 'vDjiXfvupHYNPwG', 'gGOGVMoxlnpTJ', 'lyAnMwymdwgjD', 'FYXKTsfaynbi', 'lxkpckHVaN', 'kJnudRamJLsM' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, OWTOYIZIJyNpKGH.cs | High entropy of concatenated method names: 'LnHAELgikUQp', 'NhgCvHdVYixGPY', 'vgNftLwb', 'zqDpleEs', 'PvQhnOydGnEJt', 'mdmDHkwhQFaCFE', 'kteFWzcnOtyhQF', 'XwGAQMyaw', 'nieKGkJto', 'taDWpJpYKIC' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, JhLaGgFnnm.cs | High entropy of concatenated method names: 'BBjJuiKHFhm', 'nWnwFzteBFN', 'RaRCAxpwyRa', 'MzItENDlW', 'YDTkznuIUv', 'PsTRHGIsqVWwbk', 'qzZoCbxD', 'NjPxCBqx', 'XwHpbxGutgrB', 'rAtxujftM' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, IDIkloTpeDEKz.cs | High entropy of concatenated method names: 'RtTbNdmgGNTiJ', 'BLozuJcwWEM', 'OoFXWLLvM', 'XvFCAcwvR', 'etnSPEPp', 'UXOOCPxb', 'rIWONsosurJzz', 'nJhVBmIRvWpr', 'IhDnCBNDIhQgu', 'WKXfGVvaFVuw' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, pGsFKCRggcflWBU.cs | High entropy of concatenated method names: 'csbRpcNXkOoIzfw', 'uIxOoEjoAXb', 'DluUoDhMLzH', 'tUUwOJgBgJ', 'NEFJXJnQSBtUzU', 'UwxjJuBjVUj', 'arqZntugQitKCY', 'pMAzUcupkDwAx', 'UkpnVNYbb', 'aFnDlCnh' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, ABjlTGoWuueDjB.cs | High entropy of concatenated method names: 'JYOTNpHAD', 'reVCOQvt', 'SWrZvqwwII', 'XcphJzhmw', 'tBgkbcSU', 'djJSinSyTcQt', 'rrdPoosPiIxQYUK', 'TOecdecNJHurAO', 'fHuJoGMne', 'QvaMCJSHJzNm' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, jtMfOsvbzLJS.cs | High entropy of concatenated method names: 'OXvquBcTtRB', 'PetEeZGgzc', 'ZMJZQzqsHMAFC', 'jeZuIpcLQzOB', 'VmCmXloVdlc', 'TDYuBPZqe', 'vhlrnGOvJLOdUGE', 'cTOFFsxhomDQ', 'koKsaqVAfy', 'GibQyqjRpamFc' |
Source: 0.2.exe006.exe.12519ac0.2.raw.unpack, TfVjXoNYBK.cs | High entropy of concatenated method names: 'fFjUeBGQwOKqkzc', 'OrEmJMyvye', 'MAZQLNineBcsV', 'QPCJoljv', 'zhxYlSHoVzR', 'PXxycCLxRlyijtw', 'lJtzQfajOpwUXNH', 'EHAsFLLiXxENiP', 'sWLCLGSekxOknF', 'aEeFecsEqayKbT' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, qsdQmnOoVClj.cs | High entropy of concatenated method names: 'BBZkvyAPXc', 'RGrLJYfTz', 'DQVngFtARgbT', 'JufAgWuMTPRzf', 'DewXSjoxkExPsGP', 'vkxYhQdY', 'wERkAEnBKqVUIJk', 'MJbCReoxMUgBGN', 'BXZVeXNjAKOiQ', 'lmbNfVHCWhSQTXg' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, srWopDvYJJOjOnI.cs | High entropy of concatenated method names: 'uimypVWDtvrBM', 'qKQlldlrakIFge', 'ncjdWsAM', 'JWUTutMuLQTESd', 'eADICpjo', 'yGTHXqAqycbOJS', 'gYOuQKBUyhyWpsK', 'aibUnaEWUPdGqCo', 'hGbdbpXiwmV', 'ZULxneAghxJG' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, XrMMxtush.cs | High entropy of concatenated method names: 'dwVYqImEIhTDpP', 'KpXdLLHt', 'lXvRBCdIIcKswUU', 'lrBSqUBwImDWO', 'eWCVmSNUCGD', 'uMFLOUDsa', 'GbJRVyJOyHt', 'yopbiBXQouOfZp', 'wYjTVuJQbLVwPL', 'HwRHORVmmBUKgL' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, hBbQNQJD.cs | High entropy of concatenated method names: '_003CStart_003Eb__1_0', '_003CUninstall_003Eb__2_0', '_003CLoopInstall_003Eb__7_0', '_003CStartAsBypass_003Eb__10_0', 'KurqwgagxNy', 'CGaKKTHmdelMnLw', 'KQHVXscSdXLnZZ', 'tOBfuBGDwBQuf', 'fDlkjWhGc', 'KdIgnIUNEurx' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, frZPmBqczWzjyX.cs | High entropy of concatenated method names: '_003CScreenShot_003Eb__16_0', 'PxZzaRzv', 'RLamSbrSfiZhgX', 'QyWViugRl', 'JKpSZYfvl', 'baDKXegDQyTjaSi', 'ueNsltpZIQCA', 'JtmuZfqu', 'xDOcBntaj', 'jxdBitMhkdC' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, xUOyeShR.cs | High entropy of concatenated method names: 'DbVGEuzydnVE', 'uOaMwvWnTrZWN', 'qTftniuklHFU', 'RQalZANZAYR', 'mvojkvkqUIe', 'uhWqKcTHbZEWtFA', 'AAqvNXAnFAB', 'UdAImcqre', 'PXEKuNqRqev', 'qTSjkXhikJ' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, JLFJyQOxrUocHMR.cs | High entropy of concatenated method names: 'BesGKPjZklF', 'JsABkLHTIdxtom', 'GvZiLNwEQ', 'jmubgZNKYnzUm', 'wEyPXgzSYDcdKC', 'cMnjUAYNrbEjiPy', 'mJimHPggk', 'ROqyCPLPvbMlR', 'XqGoTwQCZrqUbP', 'NfGzniKXtZpYTU' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, iKlbjEWF.cs | High entropy of concatenated method names: 'oREAjAFwuPLSSMF', 'ZwcsRkGQwxz', 'sNpajGqQZIzlfL', 'COkQxfGJHtMg', 'LnEmBPEh', 'kiMWpvRxqNGF', 'BMgBKmDh', 'WZmEmENkPGxbe', 'EbpKsKCz', 'yHlsFzESdtEL' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, JPENuWcmsm.cs | High entropy of concatenated method names: 'rciNtryioDyxr', 'ydwqwguTCB', 'XYPTHQscVbsxXh', 'GNLMLRNyvtfw', 'FnXZhXWTiPhnGVW', 'GfYJWahHqpYKZT', 'bUwWhDSPAKG', 'yeYEwqKpNGm', 'fFQjsyLtOpF', 'KyokoQYyPCi' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, YNztyhHeKkmQHuK.cs | High entropy of concatenated method names: 'QOdKPQKDllsyRlV', 'bXonLTWHVeoW', 'IulNJGRguhID', 'HMoJMZOFokGXlwr', 'pkcnccrHkHe', 'AhqgjPLK', 'LSPHUTKeqY', 'ZKEwfPTfV', 'ZEuJFHuanVkhD', 'SNfIJgctjVfq' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, aBntsXuMmjIFHIP.cs | High entropy of concatenated method names: 'tXkUzvNYRAowV', 'lfagTZlKYVLotM', 'boNLdNsydu', 'nObrjxqtycfb', 'pyjyOILCAKpMbl', 'fsgwlpmWihmOxz', 'kwNYWeeukV', 'bnElfHMyNGwjp', 'DcARcuNCmZtyCOO', 'xwbCNyRw' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, bwAaLGyc.cs | High entropy of concatenated method names: 'jkaiIzFGVBHqhz', 'XbXawtov', 'KukIziUBcb', 'sjdmnGafMhMt', 'vDjiXfvupHYNPwG', 'gGOGVMoxlnpTJ', 'lyAnMwymdwgjD', 'FYXKTsfaynbi', 'lxkpckHVaN', 'kJnudRamJLsM' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, OWTOYIZIJyNpKGH.cs | High entropy of concatenated method names: 'LnHAELgikUQp', 'NhgCvHdVYixGPY', 'vgNftLwb', 'zqDpleEs', 'PvQhnOydGnEJt', 'mdmDHkwhQFaCFE', 'kteFWzcnOtyhQF', 'XwGAQMyaw', 'nieKGkJto', 'taDWpJpYKIC' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, JhLaGgFnnm.cs | High entropy of concatenated method names: 'BBjJuiKHFhm', 'nWnwFzteBFN', 'RaRCAxpwyRa', 'MzItENDlW', 'YDTkznuIUv', 'PsTRHGIsqVWwbk', 'qzZoCbxD', 'NjPxCBqx', 'XwHpbxGutgrB', 'rAtxujftM' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, IDIkloTpeDEKz.cs | High entropy of concatenated method names: 'RtTbNdmgGNTiJ', 'BLozuJcwWEM', 'OoFXWLLvM', 'XvFCAcwvR', 'etnSPEPp', 'UXOOCPxb', 'rIWONsosurJzz', 'nJhVBmIRvWpr', 'IhDnCBNDIhQgu', 'WKXfGVvaFVuw' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, pGsFKCRggcflWBU.cs | High entropy of concatenated method names: 'csbRpcNXkOoIzfw', 'uIxOoEjoAXb', 'DluUoDhMLzH', 'tUUwOJgBgJ', 'NEFJXJnQSBtUzU', 'UwxjJuBjVUj', 'arqZntugQitKCY', 'pMAzUcupkDwAx', 'UkpnVNYbb', 'aFnDlCnh' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, ABjlTGoWuueDjB.cs | High entropy of concatenated method names: 'JYOTNpHAD', 'reVCOQvt', 'SWrZvqwwII', 'XcphJzhmw', 'tBgkbcSU', 'djJSinSyTcQt', 'rrdPoosPiIxQYUK', 'TOecdecNJHurAO', 'fHuJoGMne', 'QvaMCJSHJzNm' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, jtMfOsvbzLJS.cs | High entropy of concatenated method names: 'OXvquBcTtRB', 'PetEeZGgzc', 'ZMJZQzqsHMAFC', 'jeZuIpcLQzOB', 'VmCmXloVdlc', 'TDYuBPZqe', 'vhlrnGOvJLOdUGE', 'cTOFFsxhomDQ', 'koKsaqVAfy', 'GibQyqjRpamFc' |
Source: 0.2.exe006.exe.12596ae8.1.raw.unpack, TfVjXoNYBK.cs | High entropy of concatenated method names: 'fFjUeBGQwOKqkzc', 'OrEmJMyvye', 'MAZQLNineBcsV', 'QPCJoljv', 'zhxYlSHoVzR', 'PXxycCLxRlyijtw', 'lJtzQfajOpwUXNH', 'EHAsFLLiXxENiP', 'sWLCLGSekxOknF', 'aEeFecsEqayKbT' |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\schtasks.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /C SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Inkscape Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo 5 /tn "Paint.NET Update" /tr "C:\Users\user\AppData\Roaming\xdwdInkscape.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\exe006.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /CrEAte /F /sc OnLoGoN /rl HighEst /tn "Inkscape Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo 5 /tn "Paint.NET Update" /tr "C:\Users\user\AppData\Roaming\xdwdInkscape.exe" /RL HIGHEST | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Inkscape Upgrade" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Users\user\AppData\Roaming\xdwdInkscape.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe scHTaSks /Run /I /TN "Inkscape Upgrade" | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe | Process created: C:\Windows\System32\cmd.exe "CMD" /c SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST & exit | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\schtasks.exe SchTaSKs /create /f /sc minute /mo -1 /tn "QuickBooks Upgrade" /tr "C:\Users\user\AppData\Local\xdwdMicrosoft Paint.exe" /RL HIGHEST | |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | |