Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/1452 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/1452expand_integer_pow_expressionsThe |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/2152 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/2152skip_vs_constant_register_zeroIn |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/3246 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/3246allow_clear_for_robust_resource_initSome |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/3682 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/3682GL_USES_FRAG_COLORGL_USES_FRAG_DATA_SECONDARY_COLORGL_USES_SECONDARGL_USES_F |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/5007 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://anglebug.com/5007disable_anisotropic_filteringDisable |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://crbug.com/398694 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://crbug.com/398694Disable |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://crbug.com/941620 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: http://crbug.com/941620allow_translate_uniform_block_to_structured_bufferThere |
Source: git-bash.exe.2.dr | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04 |
Source: git-bash.exe.2.dr | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0V |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://crl.globalsign.com/gsgccr45codesignca2020.crl0 |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: git-bash.exe.2.dr | String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y |
Source: git-bash.exe.2.dr | String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0 |
Source: git-bash.exe.2.dr | String found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: git-bash.exe.2.dr | String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0# |
Source: git-bash.exe.2.dr | String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0# |
Source: git-bash.exe.2.dr | String found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0# |
Source: axvlc.dll.2.dr | String found in binary or memory: http://gcc.gnu.org/bugs.html): |
Source: powershell.exe, 00000005.00000002.2312861299.000000000614B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: git-bash.exe.2.dr | String found in binary or memory: http://ocsp.comodoca.com0 |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://ocsp.digicert.com0 |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://ocsp.globalsign.com/gsgccr45codesignca20200V |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://ocsp.globalsign.com/rootr30; |
Source: git-bash.exe.2.dr | String found in binary or memory: http://ocsp.sectigo.com0 |
Source: powershell.exe, 00000005.00000002.2303628869.0000000005236000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://s.symcb.com/universal-root.crl0 |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://s.symcd.com06 |
Source: powershell.exe, 00000005.00000002.2303628869.00000000050E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45codesignca2020.crt0= |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://secure.globalsign.com/cacert/root-r3.crt06 |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0( |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0 |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com0; |
Source: powershell.exe, 00000005.00000002.2303628869.0000000005236000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: powershell.exe, 00000005.00000002.2303628869.00000000050E1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore6lB |
Source: libGLESv2.dll.2.dr | String found in binary or memory: https://chromium.googlesource.com/angle/angle/ |
Source: powershell.exe, 00000005.00000002.2312861299.000000000614B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000005.00000002.2312861299.000000000614B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000005.00000002.2312861299.000000000614B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: libGLESv2.dll.2.dr | String found in binary or memory: https://crbug.com/593024 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: https://crbug.com/593024select_view_in_geometry_shaderThe |
Source: libGLESv2.dll.2.dr | String found in binary or memory: https://crbug.com/650547 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: https://crbug.com/650547call_clear_twiceUsing |
Source: libGLESv2.dll.2.dr | String found in binary or memory: https://crbug.com/655534 |
Source: libGLESv2.dll.2.dr | String found in binary or memory: https://crbug.com/655534use_system_memory_for_constant_buffersCopying |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: https://d.symcb.com/cps0% |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: https://d.symcb.com/rpa0 |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: https://d.symcb.com/rpa0. |
Source: powershell.exe, 00000005.00000002.2303628869.0000000005236000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000005.00000002.2303628869.00000000057A5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000005.00000002.2312861299.000000000614B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: Setup.msi, 46463c.msi.2.dr | String found in binary or memory: https://platiindustries.com/licenseUser.phpx |
Source: git-bash.exe.2.dr | String found in binary or memory: https://sectigo.com/CPS0 |
Source: smartgit-updater.exe.2.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: npvlc.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_mosaic_bridge_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_rtp_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: chrome_elf.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libvlccore.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: Qt5Gui.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_autodel_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: axvlc.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_chromecast_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_dummy_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_transcode_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_record_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_bridge_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_gather_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: Qt5Core.dll.2.dr | Static PE information: Number of sections : 13 > 10 |
Source: libstream_out_duplicate_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_smem_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_stats_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_display_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: git-bash.exe.2.dr | Static PE information: Number of sections : 13 > 10 |
Source: libstream_out_cycle_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_setid_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_standard_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_es_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_description_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: libstream_out_chromaprint_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: git-cmd.exe.2.dr | Static PE information: Number of sections : 13 > 10 |
Source: libstream_out_delay_plugin.dll.2.dr | Static PE information: Number of sections : 12 > 10 |
Source: api-ms-win-crt-multibyte-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-filesystem-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-convert-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-math-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-string-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-heap-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-conio-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-runtime-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-rtlsupport-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-environment-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-process-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-sysinfo-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-private-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-stdio-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-util-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-synch-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-timezone-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-string-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-synch-l1-2-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-profile-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-locale-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-time-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windows.ui.immersive.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: axvlc.dll.2.dr | Static PE information: section name: .buildid |
Source: axvlc.dll.2.dr | Static PE information: section name: /4 |
Source: libvlccore.dll.2.dr | Static PE information: section name: .buildid |
Source: libvlccore.dll.2.dr | Static PE information: section name: /4 |
Source: npvlc.dll.2.dr | Static PE information: section name: .buildid |
Source: npvlc.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_autodel_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_autodel_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_bridge_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_bridge_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_chromaprint_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_chromaprint_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_chromecast_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_chromecast_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_cycle_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_cycle_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_delay_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_delay_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_description_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_description_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_display_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_display_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_dummy_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_dummy_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_duplicate_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_duplicate_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_es_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_es_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_gather_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_gather_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_mosaic_bridge_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_mosaic_bridge_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_record_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_record_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_rtp_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_rtp_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_setid_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_setid_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_smem_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_smem_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: chrome_elf.dll.2.dr | Static PE information: section name: .00cfg |
Source: chrome_elf.dll.2.dr | Static PE information: section name: .crthunk |
Source: chrome_elf.dll.2.dr | Static PE information: section name: .gehcont |
Source: chrome_elf.dll.2.dr | Static PE information: section name: .oldntma |
Source: chrome_elf.dll.2.dr | Static PE information: section name: CPADinfo |
Source: UnRar.exe.2.dr | Static PE information: section name: _RDATA |
Source: libstream_out_standard_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_standard_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_stats_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_stats_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: libstream_out_transcode_plugin.dll.2.dr | Static PE information: section name: .buildid |
Source: libstream_out_transcode_plugin.dll.2.dr | Static PE information: section name: /4 |
Source: oneds.dll.2.dr | Static PE information: section name: .00cfg |
Source: oneds.dll.2.dr | Static PE information: section name: .retplne |
Source: oneds.dll.2.dr | Static PE information: section name: _RDATA |
Source: libGLESv2.dll.2.dr | Static PE information: section name: .00cfg |
Source: libGLESv2.dll.2.dr | Static PE information: section name: _RDATA |
Source: Qt5Core.dll.2.dr | Static PE information: section name: /4 |
Source: Qt5Core.dll.2.dr | Static PE information: section name: /20 |
Source: Qt5Core.dll.2.dr | Static PE information: section name: /30 |
Source: Qt5Gui.dll.2.dr | Static PE information: section name: /4 |
Source: Qt5Gui.dll.2.dr | Static PE information: section name: /14 |
Source: vcruntime140.dll.2.dr | Static PE information: section name: _RDATA |
Source: smartgit-updater.exe.2.dr | Static PE information: section name: .xdata |
Source: git-bash.exe.2.dr | Static PE information: section name: .xdata |
Source: git-bash.exe.2.dr | Static PE information: section name: .debug |
Source: git-cmd.exe.2.dr | Static PE information: section name: .xdata |
Source: git-cmd.exe.2.dr | Static PE information: section name: .debug |
Source: MSI7718.tmp.2.dr | Static PE information: section name: .fptable |
Source: MSI5109.tmp.2.dr | Static PE information: section name: .fptable |
Source: MSI5178.tmp.2.dr | Static PE information: section name: .fptable |
Source: MSI51B7.tmp.2.dr | Static PE information: section name: .fptable |
Source: MSI51E7.tmp.2.dr | Static PE information: section name: .fptable |
Source: MSI5246.tmp.2.dr | Static PE information: section name: .fptable |
Source: MSI5276.tmp.2.dr | Static PE information: section name: .fptable |
Source: MSI6F46.tmp.2.dr | Static PE information: section name: .fptable |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-bash.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI5246.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-cmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_stats_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_autodel_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Gui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\msvcp140.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_record_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_smem_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libGLESv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgitc.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\npvlc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI7718.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_transcode_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\UnRar.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_bridge_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_es_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromaprint_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_gather_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_setid_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI6F46.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit-updater.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_display_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_description_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\libvlccore.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI5178.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_cycle_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\oneds.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_standard_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI5276.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI5109.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\axvlc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\jvm.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_duplicate_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_mosaic_bridge_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI51B7.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_rtp_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSI51E7.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromecast_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\CEPHtmluser.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_dummy_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\chrome_elf.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140_1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_delay_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-bash.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-cmd.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI5246.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_stats_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_autodel_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Gui.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-math-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\msvcp140.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_record_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_smem_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libGLESv2.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgitc.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\npvlc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI7718.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_transcode_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\UnRar.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_bridge_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_es_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromaprint_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_gather_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_setid_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-time-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-private-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI6F46.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-multibyte-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit-updater.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-locale-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_display_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_description_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-runtime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\libvlccore.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI5178.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_cycle_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\oneds.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_standard_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI5276.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI5109.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\axvlc.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\jvm.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_duplicate_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Core.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_mosaic_bridge_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI51B7.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-process-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_rtp_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSI51E7.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromecast_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\CEPHtmluser.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_dummy_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\chrome_elf.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140_1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_delay_plugin.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-stdio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |