Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009D4049 | 0_2_009D4049 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009DC170 | 0_2_009DC170 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009C4670 | 0_2_009C4670 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009B92A0 | 0_2_009B92A0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009F0080 | 0_2_009F0080 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A181A0 | 0_2_00A181A0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A24110 | 0_2_00A24110 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A162EB | 0_2_00A162EB |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009FA2C0 | 0_2_009FA2C0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A442D4 | 0_2_00A442D4 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009C0239 | 0_2_009C0239 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009C8240 | 0_2_009C8240 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009C8380 | 0_2_009C8380 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A023C0 | 0_2_00A023C0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A18440 | 0_2_00A18440 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A1C7C5 | 0_2_00A1C7C5 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A16746 | 0_2_00A16746 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A248D0 | 0_2_00A248D0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009CE830 | 0_2_009CE830 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A6E90D | 0_2_00A6E90D |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009B8A80 | 0_2_009B8A80 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009C6AF7 | 0_2_009C6AF7 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A46A58 | 0_2_00A46A58 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A80B04 | 0_2_00A80B04 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A24B70 | 0_2_00A24B70 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009F8E90 | 0_2_009F8E90 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009F0E00 | 0_2_009F0E00 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A48E4A | 0_2_00A48E4A |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A14FA7 | 0_2_00A14FA7 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A14FB4 | 0_2_00A14FB4 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A58FE0 | 0_2_00A58FE0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A1CF3F | 0_2_00A1CF3F |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009CAF50 | 0_2_009CAF50 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A012A0 | 0_2_00A012A0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A1D2C6 | 0_2_00A1D2C6 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A59252 | 0_2_00A59252 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A1533B | 0_2_00A1533B |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009F3300 | 0_2_009F3300 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009B5330 | 0_2_009B5330 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009F5400 | 0_2_009F5400 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A6B47B | 0_2_00A6B47B |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A635A3 | 0_2_00A635A3 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A3F5F0 | 0_2_00A3F5F0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A595C4 | 0_2_00A595C4 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009CF570 | 0_2_009CF570 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A1D557 | 0_2_00A1D557 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009F1630 | 0_2_009F1630 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A637D2 | 0_2_00A637D2 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A5B817 | 0_2_00A5B817 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A23860 | 0_2_00A23860 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A5986E | 0_2_00A5986E |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A79879 | 0_2_00A79879 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A1D990 | 0_2_00A1D990 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A29908 | 0_2_00A29908 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009C9ABA | 0_2_009C9ABA |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009BDAB0 | 0_2_009BDAB0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A43AE5 | 0_2_00A43AE5 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009C5AC0 | 0_2_009C5AC0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009CDAF0 | 0_2_009CDAF0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009BBA60 | 0_2_009BBA60 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A59B35 | 0_2_00A59B35 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A71B71 | 0_2_00A71B71 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A15C84 | 0_2_00A15C84 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A69CD0 | 0_2_00A69CD0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A23C70 | 0_2_00A23C70 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A59DF0 | 0_2_00A59DF0 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A15EA8 | 0_2_00A15EA8 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_009F3E80 | 0_2_009F3E80 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A67E46 | 0_2_00A67E46 |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Code function: 0_2_00A17FA0 | 0_2_00A17FA0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005C4049 | 42_2_005C4049 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005B4670 | 42_2_005B4670 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005CBD00 | 42_2_005CBD00 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005E0080 | 42_2_005E0080 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00614110 | 42_2_00614110 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_006081A0 | 42_2_006081A0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005B8240 | 42_2_005B8240 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_006062EB | 42_2_006062EB |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005EA2C0 | 42_2_005EA2C0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_006342D4 | 42_2_006342D4 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005F23C0 | 42_2_005F23C0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005B8380 | 42_2_005B8380 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00608440 | 42_2_00608440 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005B05AA | 42_2_005B05AA |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00606746 | 42_2_00606746 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_0060C7C5 | 42_2_0060C7C5 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005BE830 | 42_2_005BE830 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_006148D0 | 42_2_006148D0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_0065E90D | 42_2_0065E90D |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005B69E0 | 42_2_005B69E0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00636A58 | 42_2_00636A58 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005A8A80 | 42_2_005A8A80 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00614B70 | 42_2_00614B70 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00670B04 | 42_2_00670B04 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00638E4A | 42_2_00638E4A |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005E0E00 | 42_2_005E0E00 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005E8E90 | 42_2_005E8E90 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005BAF50 | 42_2_005BAF50 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_0060CF3F | 42_2_0060CF3F |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00648FE0 | 42_2_00648FE0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00604FA7 | 42_2_00604FA7 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00604FB4 | 42_2_00604FB4 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00649252 | 42_2_00649252 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_0060D2C6 | 42_2_0060D2C6 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005A92A0 | 42_2_005A92A0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005F12A0 | 42_2_005F12A0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_0060533B | 42_2_0060533B |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005E3300 | 42_2_005E3300 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005A5330 | 42_2_005A5330 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005E5400 | 42_2_005E5400 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005BF570 | 42_2_005BF570 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_0060D557 | 42_2_0060D557 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_0062F5F0 | 42_2_0062F5F0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_006535A3 | 42_2_006535A3 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005E1630 | 42_2_005E1630 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_006537D2 | 42_2_006537D2 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00613860 | 42_2_00613860 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00669879 | 42_2_00669879 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_0064B817 | 42_2_0064B817 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00619908 | 42_2_00619908 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_0060D990 | 42_2_0060D990 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005ABA60 | 42_2_005ABA60 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00633AE5 | 42_2_00633AE5 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005B5AC0 | 42_2_005B5AC0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005BDAF0 | 42_2_005BDAF0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005B9ABA | 42_2_005B9ABA |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005ADAB0 | 42_2_005ADAB0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00661B71 | 42_2_00661B71 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005B1B7F | 42_2_005B1B7F |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00613C70 | 42_2_00613C70 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00659CD0 | 42_2_00659CD0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00605C84 | 42_2_00605C84 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00605EA8 | 42_2_00605EA8 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_005E3E80 | 42_2_005E3E80 |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Code function: 42_2_00607FA0 | 42_2_00607FA0 |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="92"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="332"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="420"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="496"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="504"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="564"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="632"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="640"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="752"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="780"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="788"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="872"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="924"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="992"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="444"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="732"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="280"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1032"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1056"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1068"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1148"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1188"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1232"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1324"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1384"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1416"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1424"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1460"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1584"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1612"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1660"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1688"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1700"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1820"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1836"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1936"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1944"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1952"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2024"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2096"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2152"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2188"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2204"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2240"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2392"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2400"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2440"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2484"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2492"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2528"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2588"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2596"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2628"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2768"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2868"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2932"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3260"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3512"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3696"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3756"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3984"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2456"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4132"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4800"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4572"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5152"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5932"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="6708"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="6792"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="6836"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="6960"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3584"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5500"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5280"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4296"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4820"::GetOwner |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5840"::GetOwner |
Source: C:\Windows\SysWOW64\systeminfo.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\SysWOW64\systeminfo.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4"::GetOwner |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1440"::GetOwner |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1440"::GetOwner |
Source: C:\Windows\SysWOW64\systeminfo.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\SysWOW64\systeminfo.exe | WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="92"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="332"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="420"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="496"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="504"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="564"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="632"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="640"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="752"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="780"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="788"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="872"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="924"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="992"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="444"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="732"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="280"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1032"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1056"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1068"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1148"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1188"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1232"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1324"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1384"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1416"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1424"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1460"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1584"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1612"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1660"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1688"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1700"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1820"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1836"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1936"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1944"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="1952"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2024"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2096"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2152"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2188"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2204"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2240"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2392"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2400"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2440"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2484"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2492"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2528"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2588"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2596"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2628"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2768"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2868"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2932"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3260"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3512"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3696"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3756"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3984"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="2456"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4132"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4800"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4572"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5152"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5932"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="6708"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="6792"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="6836"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="6960"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="3584"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5500"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5280"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4296"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="4820"::GetOwner |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecMethod - root\cimv2 : \\user-PC\root\cimv2:Win32_Process.Handle="5840"::GetOwner |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = 'XKVKNK9SXR.EXE' |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = 'XKVKNK9SXR.EXE' |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = 'XKVKNK9SXR.EXE' |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = 'XKVKNK9SXR.EXE' |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = 'XKVKNK9SXR.EXE' |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = 'XKVKNK9SXR.EXE' |
Source: unknown | Process created: C:\Users\user\Desktop\xKvkNk9SXR.exe "C:\Users\user\Desktop\xKvkNk9SXR.exe" | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c tasklist /v /fo csv | findstr /i "dcdcf" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /v /fo csv | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /i "dcdcf" | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start=auto | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start=auto | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c sc create SqlBakup binPath= "C:\Documents and Settings\user\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc create SqlBakup binPath= "C:\Documents and Settings\user\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ver | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd "%SystemDrive%\Users\%username%\AppData\"&S-2153.bat | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\S-8459.vbs" | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c schtasks /create /sc minute /mo 6 /tn "Microsoft_Auto_Scheduler" /tr "'C:\Users\%username%\AppData\S-2153.bat'" /f | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 6 /tn "Microsoft_Auto_Scheduler" /tr "'C:\Users\user\AppData\S-2153.bat'" /f | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo %date%-%time% | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo|find /i "os name" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\systeminfo.exe systeminfo | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /C echo C:\Users\user\AppData\S-6748.bat | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /i "os name" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\S-6748.bat" " | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /v | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I /c "dcdcf" | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe C:\Windows\SYSTEM32\cmd.exe /c ""C:\Users\user\AppData\S-2153.bat"" | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo|find /i "original" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\systeminfo.exe systeminfo | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /i "original" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ver | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\S-8459.vbs" | |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /C echo C:\Users\user\AppData\S-6748.bat | |
Source: C:\Windows\SysWOW64\find.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\S-6748.bat" " | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /v | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I /c "dcdcf" | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c tasklist /v /fo csv | findstr /i "dcdcf" | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start=auto | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c sc create SqlBakup binPath= "C:\Documents and Settings\user\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ver | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd "%SystemDrive%\Users\%username%\AppData\"&S-2153.bat | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c schtasks /create /sc minute /mo 6 /tn "Microsoft_Auto_Scheduler" /tr "'C:\Users\%username%\AppData\S-2153.bat'" /f | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo %date%-%time% | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo|find /i "os name" | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo|find /i "original" | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ver | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /v /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /i "dcdcf" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start=auto | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc create SqlBakup binPath= "C:\Documents and Settings\user\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\S-8459.vbs" | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /C echo C:\Users\user\AppData\S-6748.bat | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\S-6748.bat" " | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 6 /tn "Microsoft_Auto_Scheduler" /tr "'C:\Users\user\AppData\S-2153.bat'" /f | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /i "os name" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /v | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I /c "dcdcf" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\S-8459.vbs" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /i "original" | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /C echo C:\Users\user\AppData\S-6748.bat | |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\S-6748.bat" " | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /v | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I /c "dcdcf" | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: dsrole.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wbem\WmiPrvSE.exe | Section loaded: esscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\systeminfo.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\System32\cmd.exe | Section loaded: cmdext.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll | |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: apphelp.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: netapi32.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: wininet.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: samcli.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: dsrole.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c tasklist /v /fo csv | findstr /i "dcdcf" | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start=auto | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c sc create SqlBakup binPath= "C:\Documents and Settings\user\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ver | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd "%SystemDrive%\Users\%username%\AppData\"&S-2153.bat | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c schtasks /create /sc minute /mo 6 /tn "Microsoft_Auto_Scheduler" /tr "'C:\Users\%username%\AppData\S-2153.bat'" /f | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo %date%-%time% | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo|find /i "os name" | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo|find /i "original" | Jump to behavior |
Source: C:\Users\user\Desktop\xKvkNk9SXR.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ver | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /v /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /i "dcdcf" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start=auto | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc create SqlBakup binPath= "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\sc.exe sc create SqlBakup binPath= "C:\Documents and Settings\user\Start Menu\Programs\Startup\Xinfecter.exe" start= auto | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\S-8459.vbs" | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /C echo C:\Users\user\AppData\S-6748.bat | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\S-6748.bat" " | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /sc minute /mo 6 /tn "Microsoft_Auto_Scheduler" /tr "'C:\Users\user\AppData\S-2153.bat'" /f | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /i "os name" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /v | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I /c "dcdcf" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 15 /nobreak | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /fi "ImageName eq xKvkNk9SXR.exe" /fo csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /I "xKvkNk9SXR.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\S-8459.vbs" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe find /i "original" | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /C echo C:\Users\user\AppData\S-6748.bat | |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\S-6748.bat" " | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /v | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I /c "dcdcf" | |