Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\snmptrap.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Spectrum.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Locator.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7z.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\AppVClient.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zG.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\SysWOW64\perfhost.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msiexec.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\Uninstall.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\FXSSVC.exe | |
Source: C:\Users\user\AppData\Local\Temp\x.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\SensorDataService.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msdtc.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | System file written: C:\Windows\System32\alg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.132\117.0.5938.132_chrome_installer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zFM.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0040E6A0 | 1_2_0040E6A0 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0042D975 | 1_2_0042D975 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0040FCE0 | 1_2_0040FCE0 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_004221C5 | 1_2_004221C5 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_004362D2 | 1_2_004362D2 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_004803DA | 1_2_004803DA |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0043242E | 1_2_0043242E |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_004225FA | 1_2_004225FA |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0045E616 | 1_2_0045E616 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_004166E1 | 1_2_004166E1 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0043878F | 1_2_0043878F |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00436844 | 1_2_00436844 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00480857 | 1_2_00480857 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00418808 | 1_2_00418808 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00468889 | 1_2_00468889 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0042CB21 | 1_2_0042CB21 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00436DB6 | 1_2_00436DB6 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00416F9E | 1_2_00416F9E |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00413030 | 1_2_00413030 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0042F1D9 | 1_2_0042F1D9 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00423187 | 1_2_00423187 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00401287 | 1_2_00401287 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00421484 | 1_2_00421484 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00415520 | 1_2_00415520 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00427696 | 1_2_00427696 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00415760 | 1_2_00415760 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00421978 | 1_2_00421978 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00439AB5 | 1_2_00439AB5 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0050FCC8 | 1_2_0050FCC8 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00487DDB | 1_2_00487DDB |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00421D90 | 1_2_00421D90 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0042BDA6 | 1_2_0042BDA6 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_0040DF00 | 1_2_0040DF00 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00413FE0 | 1_2_00413FE0 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00AB00D9 | 1_2_00AB00D9 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00A76EAF | 1_2_00A76EAF |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00A751EE | 1_2_00A751EE |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00AAD580 | 1_2_00AAD580 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00AA3780 | 1_2_00AA3780 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00AAC7F0 | 1_2_00AAC7F0 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00AB39A3 | 1_2_00AB39A3 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00AA5980 | 1_2_00AA5980 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00A77B71 | 1_2_00A77B71 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00A77F80 | 1_2_00A77F80 |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Code function: 1_2_00BF9650 | 1_2_00BF9650 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 4_2_009B6EAF | 4_2_009B6EAF |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 4_2_009E5980 | 4_2_009E5980 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 4_2_009F39A3 | 4_2_009F39A3 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 4_2_009B51EE | 4_2_009B51EE |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 4_2_009ED580 | 4_2_009ED580 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 4_2_009B7F80 | 4_2_009B7F80 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 4_2_009E3780 | 4_2_009E3780 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 4_2_009EC7F0 | 4_2_009EC7F0 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 4_2_00A87FF8 | 4_2_00A87FF8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00408C60 | 5_2_00408C60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_0040DC11 | 5_2_0040DC11 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00407C3F | 5_2_00407C3F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00418CCC | 5_2_00418CCC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00406CA0 | 5_2_00406CA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_004028B0 | 5_2_004028B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_0041A4BE | 5_2_0041A4BE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00408C60 | 5_2_00408C60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00418244 | 5_2_00418244 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00402F20 | 5_2_00402F20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_004193C4 | 5_2_004193C4 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00418788 | 5_2_00418788 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00402F89 | 5_2_00402F89 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_00402B90 | 5_2_00402B90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_004073A0 | 5_2_004073A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_02762F26 | 5_2_02762F26 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_02761448 | 5_2_02761448 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_02761438 | 5_2_02761438 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_027611A8 | 5_2_027611A8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_02761198 | 5_2_02761198 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_04EA8530 | 5_2_04EA8530 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_04EAAC60 | 5_2_04EAAC60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_04EAF510 | 5_2_04EAF510 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_04EA8520 | 5_2_04EA8520 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_04EAED79 | 5_2_04EAED79 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_04EAB203 | 5_2_04EAB203 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 5_2_04EA1E51 | 5_2_04EA1E51 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_0099CA20 | 6_2_0099CA20 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_0099AA63 | 6_2_0099AA63 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_00998789 | 6_2_00998789 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_009BA810 | 6_2_009BA810 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_009979F0 | 6_2_009979F0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_009B92A0 | 6_2_009B92A0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_009B93B0 | 6_2_009B93B0 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_00997C00 | 6_2_00997C00 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_009C2D40 | 6_2_009C2D40 |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Code function: 6_2_009BEEB0 | 6_2_009BEEB0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 7_2_022A92A0 | 7_2_022A92A0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 7_2_022AEEB0 | 7_2_022AEEB0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 7_2_022A93B0 | 7_2_022A93B0 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 7_2_02287C00 | 7_2_02287C00 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 7_2_022AA810 | 7_2_022AA810 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 7_2_022B2D40 | 7_2_022B2D40 |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Code function: 7_2_022879F0 | 7_2_022879F0 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 10_2_00A939A3 | 10_2_00A939A3 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 10_2_00A85980 | 10_2_00A85980 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 10_2_00A56EAF | 10_2_00A56EAF |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 10_2_00A551EE | 10_2_00A551EE |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 10_2_00A8D580 | 10_2_00A8D580 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 10_2_00A57F80 | 10_2_00A57F80 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 10_2_00A83780 | 10_2_00A83780 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 10_2_00A8C7F0 | 10_2_00A8C7F0 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 10_2_00D38458 | 10_2_00D38458 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 12_2_00B839A3 | 12_2_00B839A3 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 12_2_00B46EAF | 12_2_00B46EAF |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 12_2_00B75980 | 12_2_00B75980 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 12_2_00B451EE | 12_2_00B451EE |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 12_2_00B7D580 | 12_2_00B7D580 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 12_2_00B47F80 | 12_2_00B47F80 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 12_2_00B73780 | 12_2_00B73780 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 12_2_00B7C7F0 | 12_2_00B7C7F0 |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Code function: 12_2_00CE8620 | 12_2_00CE8620 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_00401650 | 15_2_00401650 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_02BC2F26 | 15_2_02BC2F26 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_02BC1438 | 15_2_02BC1438 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_02BC1448 | 15_2_02BC1448 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_02BC11A8 | 15_2_02BC11A8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_02BC1198 | 15_2_02BC1198 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053C8530 | 15_2_053C8530 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053CAC60 | 15_2_053CAC60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053CF730 | 15_2_053CF730 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053CB210 | 15_2_053CB210 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053C8520 | 15_2_053C8520 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053CED78 | 15_2_053CED78 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053CED88 | 15_2_053CED88 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053CF510 | 15_2_053CF510 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053CB18D | 15_2_053CB18D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053CB203 | 15_2_053CB203 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 15_2_053C1E51 | 15_2_053C1E51 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 20_2_006B7C00 | 20_2_006B7C00 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 20_2_006DA810 | 20_2_006DA810 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 20_2_006E2D40 | 20_2_006E2D40 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 20_2_006B79F0 | 20_2_006B79F0 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 20_2_006D92A0 | 20_2_006D92A0 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 20_2_006DEEB0 | 20_2_006DEEB0 |
Source: C:\Windows\System32\AppVClient.exe | Code function: 20_2_006D93B0 | 20_2_006D93B0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 23_2_008C7C00 | 23_2_008C7C00 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 23_2_008EA810 | 23_2_008EA810 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 23_2_008C79F0 | 23_2_008C79F0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 23_2_008F2D40 | 23_2_008F2D40 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 23_2_008E92A0 | 23_2_008E92A0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 23_2_008EEEB0 | 23_2_008EEEB0 |
Source: C:\Windows\System32\FXSSVC.exe | Code function: 23_2_008E93B0 | 23_2_008E93B0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_0074A810 | 24_2_0074A810 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_00727C00 | 24_2_00727C00 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_00752D40 | 24_2_00752D40 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_007279F0 | 24_2_007279F0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_0074EEB0 | 24_2_0074EEB0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_007492A0 | 24_2_007492A0 |
Source: C:\Windows\System32\msdtc.exe | Code function: 24_2_007493B0 | 24_2_007493B0 |
Source: 15.2.RegSvcs.exe.2d30ee8.2.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.2d30ee8.2.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.3ee6458.6.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.3ee6458.6.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.2a41f6e.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.2a41f6e.1.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.2d30ee8.2.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.2d30ee8.2.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.3f0f990.5.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.3f0f990.5.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.2a41f6e.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.2a41f6e.1.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.5360000.7.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.5360000.7.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.3ee6458.6.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.3ee6458.6.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.2a41086.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.2a41086.0.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 4.2.differences.exe.3ee0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 15.2.RegSvcs.exe.5360000.7.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.5360000.7.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.2d30000.3.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.2d30000.3.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.2d30000.3.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.2d30000.3.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.3f0f990.5.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.3f0f990.5.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 15.2.RegSvcs.exe.3ee5570.4.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.3ee5570.4.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 12.2.differences.exe.3ee0000.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 15.2.RegSvcs.exe.2a41086.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 15.2.RegSvcs.exe.2a41086.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0000000C.00000002.1924522530.0000000003EE0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0000000F.00000002.2932151290.0000000002A01000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000004.00000002.1762544925.0000000003EE0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0000000F.00000002.2966793878.0000000003EE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0000000F.00000002.2971534610.0000000005360000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0000000F.00000002.2971534610.0000000005360000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0000000F.00000002.2944400846.0000000002D30000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0000000F.00000002.2944400846.0000000002D30000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0000000A.00000002.1905647858.0000000004080000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: x.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVClient.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: armsvc.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: differences.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: alg.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3_x64.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SciTE.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jjs.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jp2launcher.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: keytool.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: kinit.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: klist.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ktab.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeARMHelper.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: orbd.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jaureg.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pack200.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jucheck.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: policytool.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jusched.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaw.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: GoogleCrashHandler.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: GoogleCrashHandler64.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: GoogleUpdate.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7z.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zFM.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmid.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmiregistry.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: servertool.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ssvagent.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: tnameserv.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: unpack200.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ie_to_edge_stub.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: cookie_exporter.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: identity_helper.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: setup.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zG.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcrobatInfo.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: acrobat_sl.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedgewebview2.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_pwa_launcher.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: notification_click_helper.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdate.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateComRegisterShell64.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateCore.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateOnDemand.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateSetup.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate32.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate64.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVLP.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: OneDriveSetup.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Integrator.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroTextExtractor.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADelRCP.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADNotificationManager.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeCollabSync.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: WCChromeNativeMessagingHost.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: CRLogTransport.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: CRWindowsClientService.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Eula.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: LogTransport2.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: adobe_licensing_wf_acro.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: adobe_licensing_wf_helper_acro.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 32BitMAPIBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 64BitMAPIBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MSRMSPIBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: FullTrustNotifier.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ShowAppPickerForPDF.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: appvcleaner.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: x.exe.0.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVClient.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: armsvc.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: differences.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: alg.exe.1.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AutoIt3_x64.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SciTE.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jjs.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jp2launcher.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: keytool.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: kinit.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: klist.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ktab.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeARMHelper.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: orbd.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jaureg.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pack200.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jucheck.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: policytool.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: jusched.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: java.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaw.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: javaws.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: GoogleCrashHandler.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: GoogleCrashHandler64.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: GoogleUpdate.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: elevation_service.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: maintenanceservice.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7z.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zFM.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmid.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: rmiregistry.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: servertool.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ssvagent.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: tnameserv.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: unpack200.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ie_to_edge_stub.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: cookie_exporter.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: identity_helper.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: setup.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 7zG.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcrobatInfo.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: acrobat_sl.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedgewebview2.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_pwa_launcher.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: notification_click_helper.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: msedge_proxy.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: pwahelper.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdate.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateComRegisterShell64.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroCEF.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: SingleClientServicesUpdater.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateCore.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateOnDemand.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MicrosoftEdgeUpdateSetup.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate32.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVDllSurrogate64.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AppVLP.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: OneDriveSetup.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Integrator.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AcroTextExtractor.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADelRCP.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ADNotificationManager.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: AdobeCollabSync.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: WCChromeNativeMessagingHost.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: CRLogTransport.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: CRWindowsClientService.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Eula.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: LogTransport2.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: adobe_licensing_wf_acro.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: adobe_licensing_wf_helper_acro.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 32BitMAPIBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: 64BitMAPIBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: MSRMSPIBroker.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: FullTrustNotifier.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: ShowAppPickerForPDF.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: Acrobat.exe0.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: appvcleaner.exe.3.dr | Static PE information: Section: .reloc IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: mshtml.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: msiso.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: msimtf.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: msdart.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Section loaded: jscript9.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: drprov.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ntlanman.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: davclnt.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: davhlpr.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: browcli.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\alg.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dbghelp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: mpr.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: ntmarta.dll | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: version.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: mpr.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: secur32.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: ntmarta.dll | |
Source: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: wsock32.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: mpr.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: wininet.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: webio.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: wsock32.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: mpr.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: wininet.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Section loaded: webio.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: appvpolicy.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: samcli.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\AppVClient.exe | Section loaded: appmanagementconfiguration.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: tapi32.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: credui.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: fxstiff.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: fxsresm.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: ualapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\FXSSVC.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtctm.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtcprx.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtclog.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxclu.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: winmm.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: xolehlp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxclu.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: ktmw32.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: clusapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: resutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: comres.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: msdtcvsp1res.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: mtxoci.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: oci.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: firewallapi.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: fwbase.dll | |
Source: C:\Windows\System32\msdtc.exe | Section loaded: fwpolicyiomgr.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: hid.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: dxgi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: devobj.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\Locator.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mfplat.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: rtworkq.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: windows.devices.perception.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mediafoundation.defaultperceptionprovider.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: windows.devices.enumeration.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: structuredquery.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: windows.globalization.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: bcp47mrm.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: icu.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: mswb7.dll | |
Source: C:\Windows\System32\SensorDataService.exe | Section loaded: devdispitemprovider.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: winhttp.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\System32\snmptrap.exe | Section loaded: winrnr.dll | |
Source: armsvc.exe.1.dr | Static PE information: section name: .didat |
Source: alg.exe.1.dr | Static PE information: section name: .didat |
Source: GoogleCrashHandler64.exe.3.dr | Static PE information: section name: _RDATA |
Source: GoogleCrashHandler64.exe.3.dr | Static PE information: section name: .gxfg |
Source: GoogleCrashHandler64.exe.3.dr | Static PE information: section name: .gehcont |
Source: elevation_service.exe.3.dr | Static PE information: section name: .00cfg |
Source: elevation_service.exe.3.dr | Static PE information: section name: .gxfg |
Source: elevation_service.exe.3.dr | Static PE information: section name: .retplne |
Source: elevation_service.exe.3.dr | Static PE information: section name: _RDATA |
Source: elevation_service.exe.3.dr | Static PE information: section name: malloc_h |
Source: elevation_service.exe0.3.dr | Static PE information: section name: .00cfg |
Source: elevation_service.exe0.3.dr | Static PE information: section name: .gxfg |
Source: elevation_service.exe0.3.dr | Static PE information: section name: .retplne |
Source: elevation_service.exe0.3.dr | Static PE information: section name: _RDATA |
Source: elevation_service.exe0.3.dr | Static PE information: section name: malloc_h |
Source: maintenanceservice.exe.3.dr | Static PE information: section name: .00cfg |
Source: maintenanceservice.exe.3.dr | Static PE information: section name: .voltbl |
Source: maintenanceservice.exe.3.dr | Static PE information: section name: _RDATA |
Source: unpack200.exe.3.dr | Static PE information: section name: .00cfg |
Source: ie_to_edge_stub.exe.3.dr | Static PE information: section name: .00cfg |
Source: ie_to_edge_stub.exe.3.dr | Static PE information: section name: .gxfg |
Source: ie_to_edge_stub.exe.3.dr | Static PE information: section name: .retplne |
Source: ie_to_edge_stub.exe.3.dr | Static PE information: section name: _RDATA |
Source: cookie_exporter.exe.3.dr | Static PE information: section name: .00cfg |
Source: cookie_exporter.exe.3.dr | Static PE information: section name: .gxfg |
Source: cookie_exporter.exe.3.dr | Static PE information: section name: .retplne |
Source: cookie_exporter.exe.3.dr | Static PE information: section name: _RDATA |
Source: identity_helper.exe.3.dr | Static PE information: section name: .00cfg |
Source: identity_helper.exe.3.dr | Static PE information: section name: .gxfg |
Source: identity_helper.exe.3.dr | Static PE information: section name: .retplne |
Source: identity_helper.exe.3.dr | Static PE information: section name: _RDATA |
Source: identity_helper.exe.3.dr | Static PE information: section name: malloc_h |
Source: setup.exe.3.dr | Static PE information: section name: .00cfg |
Source: setup.exe.3.dr | Static PE information: section name: .gxfg |
Source: setup.exe.3.dr | Static PE information: section name: .retplne |
Source: setup.exe.3.dr | Static PE information: section name: LZMADEC |
Source: setup.exe.3.dr | Static PE information: section name: _RDATA |
Source: setup.exe.3.dr | Static PE information: section name: malloc_h |
Source: Acrobat.exe.3.dr | Static PE information: section name: .didat |
Source: Acrobat.exe.3.dr | Static PE information: section name: _RDATA |
Source: AcroCEF.exe.3.dr | Static PE information: section name: .didat |
Source: AcroCEF.exe.3.dr | Static PE information: section name: _RDATA |
Source: msedgewebview2.exe.3.dr | Static PE information: section name: .00cfg |
Source: msedgewebview2.exe.3.dr | Static PE information: section name: .gxfg |
Source: msedgewebview2.exe.3.dr | Static PE information: section name: .retplne |
Source: msedgewebview2.exe.3.dr | Static PE information: section name: CPADinfo |
Source: msedgewebview2.exe.3.dr | Static PE information: section name: LZMADEC |
Source: msedgewebview2.exe.3.dr | Static PE information: section name: _RDATA |
Source: msedgewebview2.exe.3.dr | Static PE information: section name: malloc_h |
Source: msedge_proxy.exe.3.dr | Static PE information: section name: .00cfg |
Source: msedge_proxy.exe.3.dr | Static PE information: section name: .gxfg |
Source: msedge_proxy.exe.3.dr | Static PE information: section name: .retplne |
Source: msedge_proxy.exe.3.dr | Static PE information: section name: _RDATA |
Source: msedge_proxy.exe.3.dr | Static PE information: section name: malloc_h |
Source: msedge_pwa_launcher.exe.3.dr | Static PE information: section name: .00cfg |
Source: msedge_pwa_launcher.exe.3.dr | Static PE information: section name: .gxfg |
Source: msedge_pwa_launcher.exe.3.dr | Static PE information: section name: .retplne |
Source: msedge_pwa_launcher.exe.3.dr | Static PE information: section name: LZMADEC |
Source: msedge_pwa_launcher.exe.3.dr | Static PE information: section name: _RDATA |
Source: msedge_pwa_launcher.exe.3.dr | Static PE information: section name: malloc_h |
Source: notification_click_helper.exe.3.dr | Static PE information: section name: .00cfg |
Source: notification_click_helper.exe.3.dr | Static PE information: section name: .gxfg |
Source: notification_click_helper.exe.3.dr | Static PE information: section name: .retplne |
Source: notification_click_helper.exe.3.dr | Static PE information: section name: CPADinfo |
Source: notification_click_helper.exe.3.dr | Static PE information: section name: _RDATA |
Source: notification_click_helper.exe.3.dr | Static PE information: section name: malloc_h |
Source: pwahelper.exe.3.dr | Static PE information: section name: .00cfg |
Source: pwahelper.exe.3.dr | Static PE information: section name: .gxfg |
Source: pwahelper.exe.3.dr | Static PE information: section name: .retplne |
Source: pwahelper.exe.3.dr | Static PE information: section name: _RDATA |
Source: pwahelper.exe.3.dr | Static PE information: section name: malloc_h |
Source: msedge_proxy.exe0.3.dr | Static PE information: section name: .00cfg |
Source: msedge_proxy.exe0.3.dr | Static PE information: section name: .gxfg |
Source: msedge_proxy.exe0.3.dr | Static PE information: section name: .retplne |
Source: msedge_proxy.exe0.3.dr | Static PE information: section name: _RDATA |
Source: msedge_proxy.exe0.3.dr | Static PE information: section name: malloc_h |
Source: pwahelper.exe0.3.dr | Static PE information: section name: .00cfg |
Source: pwahelper.exe0.3.dr | Static PE information: section name: .gxfg |
Source: pwahelper.exe0.3.dr | Static PE information: section name: .retplne |
Source: pwahelper.exe0.3.dr | Static PE information: section name: _RDATA |
Source: pwahelper.exe0.3.dr | Static PE information: section name: malloc_h |
Source: MicrosoftEdgeUpdate.exe.3.dr | Static PE information: section name: .didat |
Source: MicrosoftEdgeUpdateBroker.exe.3.dr | Static PE information: section name: .didat |
Source: MicrosoftEdgeUpdateComRegisterShell64.exe.3.dr | Static PE information: section name: .didat |
Source: MicrosoftEdgeUpdateComRegisterShell64.exe.3.dr | Static PE information: section name: _RDATA |
Source: SingleClientServicesUpdater.exe.3.dr | Static PE information: section name: .didat |
Source: SingleClientServicesUpdater.exe.3.dr | Static PE information: section name: _RDATA |
Source: AcroCEF.exe0.3.dr | Static PE information: section name: .didat |
Source: AcroCEF.exe0.3.dr | Static PE information: section name: _RDATA |
Source: SingleClientServicesUpdater.exe0.3.dr | Static PE information: section name: .didat |
Source: SingleClientServicesUpdater.exe0.3.dr | Static PE information: section name: _RDATA |
Source: MicrosoftEdgeUpdateCore.exe.3.dr | Static PE information: section name: .didat |
Source: MicrosoftEdgeUpdateOnDemand.exe.3.dr | Static PE information: section name: .didat |
Source: MicrosoftEdgeUpdateSetup.exe.3.dr | Static PE information: section name: .didat |
Source: AppVLP.exe.3.dr | Static PE information: section name: .c2r |
Source: OneDriveSetup.exe.3.dr | Static PE information: section name: .didat |
Source: AdobeCollabSync.exe.3.dr | Static PE information: section name: .didat |
Source: AdobeCollabSync.exe.3.dr | Static PE information: section name: _RDATA |
Source: adobe_licensing_wf_acro.exe.3.dr | Static PE information: section name: _RDATA |
Source: adobe_licensing_wf_helper_acro.exe.3.dr | Static PE information: section name: _RDATA |
Source: 64BitMAPIBroker.exe.3.dr | Static PE information: section name: _RDATA |
Source: MSRMSPIBroker.exe.3.dr | Static PE information: section name: .didat |
Source: MSRMSPIBroker.exe.3.dr | Static PE information: section name: .msvcjmc |
Source: Acrobat.exe0.3.dr | Static PE information: section name: .didat |
Source: setup.exe0.3.dr | Static PE information: section name: .didat |
Source: setup.exe0.3.dr | Static PE information: section name: _RDATA |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\snmptrap.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Spectrum.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\Locator.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7z.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\AppVClient.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zG.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\SysWOW64\perfhost.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msiexec.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\updater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.ShowHelp.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\Uninstall.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\FXSSVC.exe | |
Source: C:\Users\user\AppData\Local\Temp\x.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\SensorDataService.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\msdtc.exe | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | System file written: C:\Windows\System32\alg.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.132\117.0.5938.132_chrome_installer.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\7-Zip\7zFM.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | System file written: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\snmptrap.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\Spectrum.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\Locator.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\7z.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File created: C:\Windows\System32\AppVClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\7zG.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\SysWOW64\perfhost.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\msiexec.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File created: C:\Users\user\AppData\Local\subpredicate\differences.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\Uninstall.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\FXSSVC.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\SensorDataService.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\msdtc.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File created: C:\Windows\System32\alg.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.132\117.0.5938.132_chrome_installer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\7-Zip\7zFM.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\mshta.exe | File created: C:\Users\user\AppData\Local\Temp\x.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | File created: C:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\SysWOW64\mshta.exe | File written: C:\Users\user\AppData\Local\Temp\x.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Users\user\AppData\Roaming\31d53b0537b9f482.bin offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 162304 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 735820 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 737280 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 1285120 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 1286144 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 1289427 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 735744 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 31704 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Users\user\AppData\Local\Temp\autE8B0.tmp offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Users\user\AppData\Local\Temp\autE8B0.tmp offset: 196608 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Users\user\AppData\Local\Temp\avenses offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Users\user\AppData\Local\Temp\avenses offset: 196608 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Users\user\AppData\Local\Temp\avenses offset: 208896 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 95744 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 669260 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 672768 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 1220608 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 1221632 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 1224840 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 669184 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 53125 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Users\user\AppData\Local\subpredicate\differences.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\alg.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\AppVClient.exe offset: 767488 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1341004 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\AppVClient.exe offset: 0 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1344512 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | File written: C:\Windows\System32\AppVClient.exe offset: 1347720 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Windows\System32\config\systemprofile\AppData\Roaming\31d53b0537b9f482.bin offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe offset: 1792000 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe offset: 2365516 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe offset: 2365440 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe offset: 777420 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 1776128 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 2349644 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 2349568 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 677164 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 228352 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 801868 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 801792 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 43297 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 557056 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 1130572 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 1130496 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 382726 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7z.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 952832 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 1526348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 1526272 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 614020 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zFM.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 700416 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 1273932 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 1273856 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 464916 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\7zG.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 14848 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 588364 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 588288 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 5610 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\7-Zip\Uninstall.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 5630464 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 6203980 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 6203904 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 3201596 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 27136 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 600652 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 600576 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 8988 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 31744 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 605260 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 605184 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 12684 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 332800 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 906316 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 906240 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 232412 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 3571200 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 4144716 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 4144640 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 1485948 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 59362816 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 59936332 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 59936256 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 140924 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 3571200 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 4144716 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 4144640 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 1485948 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 59362816 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 59936332 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 59936256 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 140924 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 50176 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 623692 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 623616 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 24668 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 642048 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 1215564 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 1215488 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 132252 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 11459072 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 12032588 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 12032512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 4630732 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 192512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 766028 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 765952 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 95345 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 759296 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 1332812 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 1332736 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 285633 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 385536 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 959052 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 958976 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 182364 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 123904 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 697420 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 697344 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 66716 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 1102848 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 1676364 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 1676288 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 753617 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 2531840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 3105356 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 3105280 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 1150992 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 459776 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 1033292 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 1033216 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 209348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 99840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 673356 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 673280 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 69527 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 256512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 830028 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 829952 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 72028 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 521216 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 1094732 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 1094656 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 321696 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 210944 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 784460 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 784384 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 126840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 13312 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 586828 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 586752 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 2828 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 4785664 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 5359180 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 5359104 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 2430581 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 632832 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 1206348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 1206272 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 206444 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 2578944 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 3152460 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 3152384 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 16859 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 1617920 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 2191436 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 2191360 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 860981 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 258048 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 831564 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 831488 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 82352 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 5274624 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 5848140 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 5848064 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 3286540 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 185344 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 758860 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 758784 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 151349 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 26954240 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 27527756 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 27527680 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 11401068 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 4392960 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 4966476 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 4966400 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 2843313 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe offset: 1576448 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe offset: 2149964 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe offset: 2149888 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe offset: 574636 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe offset: 4318208 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe offset: 4891724 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe offset: 4891648 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe offset: 1700540 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe offset: 4318208 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe offset: 4891724 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe offset: 4891648 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe offset: 1700540 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe offset: 1404928 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe offset: 1978444 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe offset: 1978368 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe offset: 633260 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 1199616 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 1773132 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 1773056 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 513116 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 248832 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 822348 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 822272 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 121980 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\crashreporter.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 707072 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 1280588 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 1280512 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 346881 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\default-browser-agent.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 666112 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 1239628 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 1239552 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 193089 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\firefox.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 228352 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 801868 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 801792 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 43297 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\maintenanceservice.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 762368 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 1335884 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 1335808 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 239297 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 70144 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 643660 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 643584 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 32241 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\pingsender.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 279040 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 852556 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 852480 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 111633 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\plugin-container.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 55296 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 628812 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 628736 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 4108 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\private_browsing.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 403968 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 977484 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 977408 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 79009 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files\Mozilla Firefox\updater.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 224256 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 797772 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 797696 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 35826 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Check.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info.exe offset: 166400 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info.exe offset: 739916 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info.exe offset: 739840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info.exe offset: 21924 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe offset: 185856 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe offset: 759372 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe offset: 759296 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe offset: 25840 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe offset: 1624576 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe offset: 2198092 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe offset: 2198016 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe offset: 89651 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe offset: 0 | Jump to behavior |
Source: C:\Windows\System32\alg.exe | File written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe offset: 0 | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\mshta.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\subpredicate\differences.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\chrmstp.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\servertool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\pingsender.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\Spectrum.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\default-browser-agent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\LogTransport2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7z.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\crashreporter.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\64BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7zG.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Windows\System32\msiexec.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\MSRMSPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\keytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.132\notification_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\notification_click_helper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\firefox.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\updater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\kinit.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\117.0.5938.132\elevation_service.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\policytool.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\Uninstall.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\rmiregistry.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\elevation_service.exe | Dropped PE file which has not been started: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java-rmi.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\minidump-analyzer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\pack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jabswitch.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.132\117.0.5938.132_chrome_installer.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\rmid.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\7-Zip\7zFM.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\32BitMAPIBroker.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\klist.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\tnameserv.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\WindowsInstaller-KB893803-v2-x86.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\private_browsing.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jjs.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\orbd.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\SingleClientServicesUpdater.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Google\Chrome\Application\chrome_proxy.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ktab.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files\Mozilla Firefox\plugin-container.exe | Jump to dropped file |
Source: C:\Windows\System32\alg.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |