Source: regsvr32.exe, 0000000E.00000003.101876266085.00000000053B8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digic |
Source: regsvr32.exe, 00000009.00000003.101745297574.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101956821107.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101744354529.00000000050D7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101940941733.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101747125678.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748685259.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101746518370.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101751706370.0000000005100000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101741715743.00000000050EF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101752875137.0000000005102000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748153353.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102062176560.00000000057C0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG3.crt0B |
Source: powershell.exe, 0000000A.00000002.101802236942.000002A4E6A5F000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753EB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 0000000A.00000002.101802236942.000002A4E6A45000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 0000000F.00000002.102015220848.000001E27587D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.microso |
Source: regsvr32.exe, 00000009.00000003.101745297574.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101956821107.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101744354529.00000000050D7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101940941733.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101747125678.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748685259.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101746518370.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101751706370.0000000005100000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101741715743.00000000050EF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101752875137.0000000005102000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748153353.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102062176560.00000000057C0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG3.crl0 |
Source: powershell.exe, 0000000A.00000002.101798259193.000002A4DE8C5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000A.00000002.101779809519.000002A4CFD3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101896209492.0000025DB1525000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA29A8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101994038719.000001E26D311000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: regsvr32.exe, 00000009.00000003.101745297574.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101750988707.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101956821107.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101744354529.00000000050D7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101940941733.0000000005046000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101747125678.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748685259.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101746518370.00000000050C2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101751706370.0000000005100000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101741715743.00000000050EF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101752875137.0000000005102000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101748153353.00000000050C1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102062176560.00000000057C0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXzA |
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2853000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngh |
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CE851000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA14B1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D2A1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA256D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753B8000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXzA |
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2853000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlh |
Source: i9DKxTZoVd.exe, 00000000.00000003.101663444971.0000000002500000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.exe, 00000000.00000003.101663862917.000000007FD30000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.tmp, 00000001.00000000.101665254233.0000000000401000.00000020.00000001.01000000.00000004.sdmp, i9DKxTZoVd.tmp.0.dr | String found in binary or memory: http://www.innosetup.com/ |
Source: regsvr32.exe, 00000009.00000003.101952377109.00000000052BF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.00000000052BF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005554000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.intel.com/support/gfx_feedback |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005319000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005319000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.00000000055AB000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.000000000584B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.intel.com/support/gfx_feedbackx; |
Source: powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.micrm/pki/certs/MicR_2010-06-23.crt0 |
Source: powershell.exe, 0000000A.00000002.101802236942.000002A4E6A5F000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753EB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: i9DKxTZoVd.exe, 00000000.00000003.101663444971.0000000002500000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.exe, 00000000.00000003.101663862917.000000007FD30000.00000004.00001000.00020000.00000000.sdmp, i9DKxTZoVd.tmp, 00000001.00000000.101665254233.0000000000401000.00000020.00000001.01000000.00000004.sdmp, i9DKxTZoVd.tmp.0.dr | String found in binary or memory: http://www.remobjects.com/ps |
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CE851000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA14B1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D2A1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: regsvr32.exe, 00000009.00000003.101731450336.0000000005084000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953113164.0000000005239000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101732892581.0000000005084000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101733366336.0000000005098000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101953392054.0000000005255000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952282689.0000000005239000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102031668502.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101871816850.000000000545D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/news/Feed/Windows? |
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: i9DKxTZoVd.tmp, 00000007.00000003.101705778461.0000000006000000.00000004.00001000.00020000.00000000.sdmp, regsvr32.exe, regsvr32.exe, 0000000E.00000002.102062979701.00007FFB990F3000.00000002.00000001.01000000.00000007.sdmp | String found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support |
Source: regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gameplayapi.intel.com/api/games/downloadthumbnail/ |
Source: regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgames2/ |
Source: regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgames2/r |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/ |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/# |
Source: regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/. |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/C |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gameplayapi.intel.com/api/games/getagsgamesettings2/Y |
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101908630743.0000025DB9CC6000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 0000000A.00000002.101779809519.000002A4CEA7C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA16DB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXzA |
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA2853000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA2827000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pesterh |
Source: powershell.exe, 0000000A.00000002.101798259193.000002A4DE8C5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000A.00000002.101779809519.000002A4CFD3E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101896209492.0000025DB1525000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101837470212.0000025DA29A8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101994038719.000001E26D311000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.101919557191.000001E25E72F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 0000000A.00000002.101802236942.000002A4E6A5F000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.101905223523.0000025DB99C0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.102005654098.000001E2753EB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 0000000C.00000002.101837470212.0000025DA256D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oneget.org |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tst-gameplayapi.intel.com/api/games/downloadthumbnail/ |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tst-gameplayapi.intel.com/api/games/downloadthumbnail/g |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101734444126.000000000527E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005510000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgames2/ |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgames2/) |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgames2/m |
Source: regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/ |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/. |
Source: regsvr32.exe, 00000009.00000003.101734444126.0000000005286000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101952377109.000000000529F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101876830513.00000000057B8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102033434819.0000000005518000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tst-gameplayapi.intel.com/api/games/getagsgamesettings2/E |
Source: C:\Users\user\Desktop\i9DKxTZoVd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\i9DKxTZoVd.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\i9DKxTZoVd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: msimg32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\i9DKxTZoVd.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\i9DKxTZoVd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\i9DKxTZoVd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: msimg32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\regsvr32.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: pdh.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: perfos.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kdscli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kdscli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: aclayers.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc_os.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: edgegdi.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: pdh.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: powrprof.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: samcli.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: umpdc.dll | |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: perfos.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: edgegdi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: xmllite.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kdscli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ntasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Users\user\Desktop\i9DKxTZoVd.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-O75JM.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\i9DKxTZoVd.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-KU6E7.tmp\i9DKxTZoVd.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V Dynamic Memory Integration Service |
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VHyper-V Dynamic Memory Integration Service6 |
Source: regsvr32.exe, 0000000E.00000003.101835410052.0000000002FAF000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101847395804.0000000002FC8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101840433580.0000000002FE0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Sched |
Source: regsvr32.exe, 0000000E.00000003.101841221752.0000000003088000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ota Statistics3434Total Requests/Second3436User Quota Violations/Second3438System Quota Violations/Second3440Active Shells3442Active Operations3444Active Users3446Process ID1914Hyper-V VM Vid Partition1916Physical Pages Allocated1918Preferred NUMA Node Index1920Remote Physical Pages1922ClientHandles1924CompressPackTimeInUs1926CompressUnpackTimeInUs1928CompressPackInputSizeInBytes1930CompressUnpackInputSizeInBytes1932CompressPackOutputSizeInBytes1934CompressUnpackOutputSizeInBytes1936CompressUnpackUncompressedInputSizeInBytes1938CompressPackDiscardedSizeInBytes1940CompressWorkspaceSizeInBytes1942CompressScratchPoolSizeInBytes1944CryptPackTimeInUs1946CryptUnpackTimeInUs1948CryptPackInputSizeInBytes1950CryptUnpackInputSizeInBytes1952CryptPackOutputSizeInBytes1954CryptUnpackOutputSizeInBytes1956CryptScratchPoolSizeInBytesgga] |
Source: regsvr32.exe, 0000000E.00000003.101835729496.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838409957.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838372437.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101835764971.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101840971855.0000000003088000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ccessful discoveries9610Hosted Cache: Segment offers queue size9612Publication Cache: Published contents9614Local Cache: Average access time3432WSMan Quota Statistics3434Total Requests/Second3436User Quota Violations/Second3438System Quota Violations/Second3440Active Shells3442Active Operations3444Active Users3446Process ID1914Hyper-V VM Vid Partition1916Physical Pages Allocated1918Preferred NUMA Node Index1920Remote Physical Pages1922ClientHandles1924CompressPackTimeInUs1926CompressUnpackTimeInUs1928CompressPackInputSizeInBytes1930CompressUnpackInputSizeInBytes1932CompressPackOutputSizeInBytes1934CompressUnpackOutputSizeInBytes1936CompressUnpackUncompressedInputSizeInBytes1938CompressPackDiscardedSizeInBytes1940CompressWorkspaceSizeInBytes1942CompressScratchPoolSizeInBytes1944CryptPackTimeInUs1946CryptUnpackTimeInUs1948CryptPackInputSizeInBytes1950CryptUnpackInputSizeInBytes1952CryptPackOutputSizeInBytes1954CryptUnpackOutputSizeInBytes1956CryptScratchPoolSizeInBytesgga] |
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: DHyper-V Virtual Machine Bus Pipesows\ |
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V Hypervisor Logical Processors2.sys |
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 2Hyper-V VM Vid Partitionmunb3 |
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 2Hyper-V VM Vid Partitionvity |
Source: regsvr32.exe, 0000000E.00000003.101834884718.0000000002F41000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101834734505.0000000002F55000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Contex |
Source: regsvr32.exe, 0000000E.00000003.101835729496.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101834255055.000000000306B000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101835892541.0000000003069000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838409957.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101849833577.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101841368765.000000000306B000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838372437.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101841221752.0000000003088000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101838685116.000000000306B000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101834153989.0000000003031000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848P |
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: &Hyper-V Hypervisori |
Source: regsvr32.exe, 00000009.00000003.101743560036.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.000000000514F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101880620764.00000000055F3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102042264213.000000000551A000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V Virtual Machine Bus PipesJb |
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V VM Vid Partition |
Source: powershell.exe, 0000000F.00000002.101919557191.000001E25D4CB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Get-NetEventVmNetworkAdapter |
Source: regsvr32.exe, 00000009.00000003.101720053485.0000000002B7E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101711754873.0000000002B82000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101720170362.0000000002B8F000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Tr |
Source: regsvr32.exe, 0000000E.00000003.101834631814.0000000002F59000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101834336339.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101836256303.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101833974413.0000000002F63000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ets: RS-Secondary3244In - Teredo Server Error Packets: Total3246In - Teredo Server Error Packets: Header Error3248In - Teredo Server Error Packets: Source Error3250In - Teredo Server Error Packets: Destination Error3252In - Teredo Server Error Packets: Authentication Error3254Out - Teredo Server: RA-Primary3256Out - Teredo Server: RA-Secondary 3258In - Teredo Server Total Packets: Success + Error / sec3206Teredo Client3208In - Teredo Router Advertisement3210In - Teredo Bubble3212In - Teredo Data3214In - Teredo Invalid3216Out - Teredo Router Solicitation3218Out - Teredo Bubble3220Out - Teredo Data3222In - Teredo Data User Mode3224In - Teredo Data Kernel Mode3226Out - Teredo Data User Mode3228Out - Teredo Data Kernel Mode6468Hyper-V Dynamic Memory Integration Service6470Maximum Memory, Mbytes1848Bluetooth Radio1850Classic ACL bytes written/sec1852LE ACL bytes written/sec1854SCO bytes written/sec1856Classic ACL bytes read/sec1858LE ACL bytes read/sec1860SCO bytes read/sec1862Classic ACL Connections1864LE ACL Connections1866SCO Connections1868Sideband SCO Connections1870ACL flush events/sec1872LE ACL write credits1874Classic ACL write credits1876LE Scan Duty Cycle (%) - Uncoded 1M Phy1878LE Scan Window - Uncoded 1M Phy1880LE Scan Interval - Uncoded 1M Phy1882Page Scan Duty Cycle (%)1884Page Scan Window1886Page Scan Interval1888Inquiry Scan Duty Cycle (%)1890Inquiry Scan Window1892Inquiry Scan Interval1894LE Scan Duty Cycle (%) - Coded Phy1896LE Scan Window - Coded Phy1898LE Scan Interval - Coded Phy1900Bluetooth Device1902Classic ACL bytes written/sec1904LE ACL bytes written/sec1906SCO bytes written/sec1908Classic ACL bytes read/sec1910LE ACL bytes read/sec1912SCO bytes read/sec3814ServiceModelService 4.0.0.03816Calls |
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VHyper-V Dynamic Memory Integration Service |
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VHyper-V Dynamic Memory Integration Service |
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: JHyper-V Hypervisor Logical ProcessorP |
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V Virtual Machine Bus Pipes |
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: X2Hyper-V VM Vid Partition.dll>$ |
Source: regsvr32.exe, 00000009.00000003.101712142747.0000000002B35000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: kflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequenc |
Source: regsvr32.exe, 00000009.00000003.101712472154.0000000002BBB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot |
Source: regsvr32.exe, 0000000E.00000003.101834840785.0000000002F31000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ctive Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Size49244K GPA pages49262M GPA pages49281G GPA pages4930512G GPA pages49324K device pages49342M device pages49361G device pages4938512G device pages4940Attached Devices4942Device Interrupt Mappings4944I/O TLB Flushes/sec4946I/O TLB Flush Cost4948Device Interrupt Errors4950Device DMA Errors4952Device Interrupt Throttle Events4954Skipped Timer Ticks4956Partition Id4958Nested TLB Size4960Recommended Nested TLB Size4962Nested TLB Free List Size4964Nested TLB Trimmed Pages/sec4966Pages Shattered/sec4968Pages Recombined/sec4970I/O TLB Flushes Base4972Hyper-V Hypervisor Root Virtual Processor4974Total Run Time4976Hypervisor Run Time4978Remote Node Run Time4980Normalized Run Time4982Ideal Cpu4984Hypercalls/sec4986Hypercalls Cost4988Page Invalidations/sec4990Page Invalidations Cost4992Control Register Accesses/sec4994Control Register Accesses Cost4996IO Instructions/sec4998IO Instructions Cost5000HLT Instructions/sec5002HLT Instructions Cost5004MWAIT Instructions/sec5006MWAIT Instructions Cost5008CPUID Instructions/sec5010CPUID Instructions Cost5012MSR Accesses/sec5014MSR Accesses Cost5016Other Intercepts/sec5018Other Intercepts Cost5020External Interrupts/sec5022External Interrupts Cost5024Pending Interrupts/sec5026Pending Interrupts Cost5028Emulated Instructions/sec5030Emulated Instructions Cost\"9 |
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: DHyper-V Hypervisor Root Partitionows\ |
Source: regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.00000000030B5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.00000000057BA000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V Hypervisor Logical Processorc.sys9 |
Source: regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.00000000030B5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.00000000057BA000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V Hypervisor Root Partitiong |
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: &Hyper-V HypervisorC< |
Source: regsvr32.exe, 00000009.00000003.101947276329.0000000005204000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000002.102056814035.00000000012F0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.00000000030B5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.00000000057BA000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V Hypervisor Root Virtual Processori |
Source: regsvr32.exe, 0000000E.00000002.102056911334.0000000001378000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102054265581.0000000001375000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101883897736.0000000005837000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101889558229.0000000001377000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.102046538179.0000000003132000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V VM Vid PartitionZ9uj |
Source: regsvr32.exe, 00000009.00000003.101740776394.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101743560036.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.102021982749.0000000001048000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101753563395.0000000001047000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101945353633.00000000051CC000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.101959050599.0000000001047000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V Hypervisory |
Source: regsvr32.exe, 00000009.00000003.101720363736.0000000002B38000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000E.00000003.101846931416.0000000002FAD000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 6242WorkflowServiceHost 4.0.0.06244Workflows Created6246Workflows Created Per Second6248Workflows Executing6250Workflows Completed6252Workflows Completed Per Second6254Workflows Aborted6256Workflows Aborted Per Second6258Workflows In Memory6260Workflows Persisted6262Workflows Persisted Per Second6264Workflows Terminated6266Workflows Terminated Per Second6268Workflows Loaded6270Workflows Loaded Per Second6272Workflows Unloaded6274Workflows Unloaded Per Second6276Workflows Suspended6278Workflows Suspended Per Second6280Workflows Idle Per Second6282Average Workflow Load Time6284Average Workflow Load Time Base6286Average Workflow Persist Time6288Average Workflow Persist Time Base6324Terminal Services6326Active Sessions6328Inactive Sessions6330Total Sessions4806Hyper-V Hypervisor Logical Processor4808Global Time4810Total Run Time4812Hypervisor Run Time4814Hardware Interrupts/sec4816Context Switches/sec4818Inter-Processor Interrupts/sec4820Scheduler Interrupts/sec4822Timer Interrupts/sec4824Inter-Processor Interrupts Sent/sec4826Processor Halts/sec4828Monitor Transition Cost4830Context Switch Time4832C1 Transitions/sec4834% C1 Time4836C2 Transitions/sec4838% C2 Time4840C3 Transitions/sec4842% C3 Time4844Frequency4846% of Max Frequency4848Parking Status4850Processor State Flags4852Root Vp Index4854Idle Sequence Number4856Global TSC Count4858Active TSC Count4860Idle Accumulation4862Reference Cycle Count 04864Actual Cycle Count 04866Reference Cycle Count 14868Actual Cycle Count 14870Proximity Domain Id4872Posted Interrupt Notifications/sec4874Hypervisor Branch Predictor Flushes/sec4876Hypervisor L1 Data Cache Flushes/sec4878Hypervisor Immediate L1 Data Cache Flushes/sec4880Hypervisor Microarchitectural Buffer Flushes/sec4882Counter Refresh Sequence Number4884Counter Refresh Reference Time4886Idle Accumulation Snapshot4888Active Tsc Count Snapshot4890HWP Request MSR Context Switches/sec4892Guest Run Time4894Idle Time4896% Total Run Time4898% Hypervisor Run Time4900% Guest Run Time4902% Idle Time4904Total Interrupts/sec4788Hyper-V Hypervisor4790Logical Processors4792Partitions4794Total Pages4796Virtual Processors4798Monitored Notifications4800Modern Standby Entries4802Platform Idle Transitions4804HypervisorStartupCost4906Hyper-V Hypervisor Root Partition4908Virtual Processors4910Virtual TLB Pages4912Address Spaces4914Deposited Pages4916GPA Pages4918GPA Space Modifications/sec4920Virtual TLB Flush Entires/sec4922Recommended Virtual TLB Si |