Source: WidgetBoard.exe, 00000014.00000002.13651394023.00000236E6B35000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://adaptivecards.io/schemas/adaptive-card.json |
Source: explorer.exe, 0000000E.00000003.12143590504.0000000007864000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: ep_setup.exe | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: WidgetBoard.exe, 00000014.00000002.13647627723.00000236E4E5D000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13647289234.00000236E4E47000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13647993600.00000236E4E88000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13650603961.00000236E6B02000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13649499798.00000236E4EE1000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13649266539.00000236E4ED0000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648200876.00000236E4E9B000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13650938977.00000236E6B13000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648434910.00000236E4EAC000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648691521.00000236E4EBF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://account.live.com/ |
Source: explorer.exe, 0000000E.00000003.12143590504.0000000007864000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/Vh5j3k |
Source: explorer.exe, 0000000E.00000003.12143590504.0000000007864000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/odirm |
Source: ep_setup.exe, 00000001.00000003.11833924594.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, explorer.exe, 0000000C.00000002.11955389788.00007FFD656BD000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: https://api.github.com/repos/valinet/ExplorerPatcher/releases?per_page=1 |
Source: explorer.exe, 0000000E.00000003.12160188405.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12062804617.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12104924851.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12152136805.0000000007A55000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12139286268.0000000007A52000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/ |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet) |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher#donate |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/blob/master/CHANGELOG.md |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/discussions |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/discussions/1102 |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/discussions/1679 |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/issues |
Source: ep_setup.exe, 00000001.00000003.11833924594.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.11955389788.00007FFD656BD000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/issueshttps://github.com/valinet/ExplorerPatcher/discussi |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases |
Source: ep_setup.exe, 00000001.00000003.11833924594.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, explorer.exe, 0000000C.00000002.11955389788.00007FFD656BD000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/latest |
Source: explorer.exe, 0000000E.00000003.12160188405.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12062804617.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12104924851.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12152136805.0000000007A55000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12139286268.0000000007A52000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/latest/download/ep_setup.exe |
Source: explorer.exe, 0000000E.00000003.12160188405.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12062804617.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12104924851.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12152136805.0000000007A55000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12139286268.0000000007A52000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/latest/download/ep_setup.exev |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/About-advanced-settings |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Configure-updates |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/ExplorerPatcher |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Frequently-asked-questions |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Settings-management |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Simple-Window-Switcher |
Source: explorer.exe, explorer.exe, 0000000C.00000002.11955389788.00007FFD656BD000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Symbols |
Source: ep_setup.exe, 00000001.00000003.11833924594.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.11955389788.00007FFD656BD000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/SymbolsMicrosoft.Windows.Explorer |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Using-ExplorerPatcher-as-shell-extension |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Weather |
Source: ep_setup.exe, 00000001.00000003.11830373643.000001322B9B3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://go.skype.com/meetnowjoin.winshell&exp=?exp=https://go.skype.com/meetnow.winshellskype:?actio |
Source: ep_setup.exe, 00000001.00000003.11827026660.000001322BA74000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://go.skype.com/meetnowlearn.winshell |
Source: WidgetBoard.exe, 00000014.00000002.13647627723.00000236E4E5D000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13647289234.00000236E4E47000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13647993600.00000236E4E88000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13650603961.00000236E6B02000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13649499798.00000236E4EE1000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13649266539.00000236E4ED0000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648200876.00000236E4E9B000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13650938977.00000236E6B13000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648434910.00000236E4EAC000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648691521.00000236E4EBF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/ |
Source: explorer.exe, 0000000E.00000003.12160188405.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12062804617.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12104924851.0000000007A59000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12152136805.0000000007A55000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12139286268.0000000007A52000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13647627723.00000236E4E5D000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13647289234.00000236E4E47000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13647993600.00000236E4E88000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13650603961.00000236E6B02000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13649499798.00000236E4EE1000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13649266539.00000236E4ED0000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648200876.00000236E4E9B000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13650938977.00000236E6B13000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648434910.00000236E4EAC000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648691521.00000236E4EBF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.microsoftonline.com/ |
Source: explorer.exe, 0000000E.00000003.12143590504.0000000007910000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows.local/ |
Source: explorer.exe, 0000000E.00000003.12143590504.0000000007910000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows.localc |
Source: explorer.exe, 0000000E.00000003.12025005518.000000000A757000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12017307599.000000000A757000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000E.00000003.12011879661.000000000A757000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://objects.githubusercontent.com/github-production-release-asset-2e65be/394318710/5e5bb508-cbdc |
Source: ep_setup.exe, 00000001.00000003.11833924594.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, explorer.exe, 0000000C.00000002.11955389788.00007FFD656BD000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: https://raw.githubusercontent.com/valinet/ep_make/master/ep_make_safe.ps1 |
Source: WidgetBoard.exe, 00000014.00000002.13647627723.00000236E4E5D000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13647289234.00000236E4E47000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13647993600.00000236E4E88000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13650603961.00000236E6B02000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13649499798.00000236E4EE1000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13649266539.00000236E4ED0000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648200876.00000236E4E9B000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13650938977.00000236E6B13000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648434910.00000236E4EAC000.00000004.00000020.00020000.00000000.sdmp, WidgetBoard.exe, 00000014.00000002.13648691521.00000236E4EBF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://signup.live.com/ |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949438-4e0c0e0d-67bc-4c76-b75e-e0ffcead3f48.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949442-63f14d44-ec0e-40b2-aa1b-8e4a27ec10f5.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949443-062a0fa9-88c1-4e07-b6b1-8e52ff64f4f3.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949444-d3aea936-4c22-4f17-a201-02155396684d.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949445-60d12efa-a21d-40e0-b9a8-1b7a84e58944.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949447-a6658710-567e-4977-9316-a80007df3076.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949448-cd1b69af-4028-4153-8e40-288526577b58.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949449-9320c6f5-15ef-4c17-9e72-740708f4828c.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949450-7e03a3f5-580e-4414-aaeb-3a0898afd1da.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949451-269d02a3-08cb-4237-9789-f1e60fdc723d.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949452-f347fe27-5005-48f2-9c9a-899bb7b8825e.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949454-81d5d47d-1f33-4859-a112-5a64ceb549a1.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949456-04a4bdbd-ff3b-4484-bb30-8909baff8aa8.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949458-dc66775d-8bb9-4d04-838e-7f550d305c26.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949459-dfe70eba-6c2c-4b1c-b51b-27c13ce7c08c.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949460-7c132d89-efb7-457f-8810-9bf235f5737f.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949461-1f058cf3-6fdd-4aeb-80b7-68fa27b02845.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949462-f50c21dd-85dd-4d9c-a4eb-516e6cddfb1f.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949463-a427edfb-3d7f-4167-bd6f-f5019c482ea1.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949465-54dd31c6-7e3a-464a-8e64-8b54b6fb7a65.png |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156950233-ccaadb4a-2e9a-4934-b41c-acd36a7f0d9c.png |
Source: explorer.exe, 0000000E.00000003.12143590504.00000000079FA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://vsblobprodscussu5shard86.blob.core.windows.net/ |
Source: explorer.exe, 0000000E.00000003.12139286268.0000000007A52000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://vsblobprodscussu5shard86.blob.core.windows.net/b-4712e0edc5a240eabf23330d7df68e77/212EE6F6E5 |
Source: ep_setup.exe, 00000001.00000003.11823830987.000001322B6B1000.00000004.00000020.00020000.00000000.sdmp, ep_setup.exe, 00000001.00000003.11823886137.0000013228E3A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/search?hl=%s&q=weather%s%s%s%s%s%s%s%spCoreWebView2ExecuteScriptCompletedHand |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.valinet.ro |
Source: ep_setup.exe, 00000001.00000003.11823232661.000001322B7B1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.valinet.ro) |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65671640 | 12_2_00007FFD65671640 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565E500 | 12_2_00007FFD6565E500 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65668690 | 12_2_00007FFD65668690 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6567A120 | 12_2_00007FFD6567A120 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656853F0 | 12_2_00007FFD656853F0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6568FC70 | 12_2_00007FFD6568FC70 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6568F040 | 12_2_00007FFD6568F040 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6566D980 | 12_2_00007FFD6566D980 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65666BA0 | 12_2_00007FFD65666BA0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65685AC0 | 12_2_00007FFD65685AC0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6566C590 | 12_2_00007FFD6566C590 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6568E620 | 12_2_00007FFD6568E620 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A0604 | 12_2_00007FFD656A0604 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6566F5E0 | 12_2_00007FFD6566F5E0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65690540 | 12_2_00007FFD65690540 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65696530 | 12_2_00007FFD65696530 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565A4E0 | 12_2_00007FFD6565A4E0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656847D0 | 12_2_00007FFD656847D0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65690840 | 12_2_00007FFD65690840 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65688820 | 12_2_00007FFD65688820 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A0808 | 12_2_00007FFD656A0808 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656B57F0 | 12_2_00007FFD656B57F0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A46C0 | 12_2_00007FFD656A46C0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A26F8 | 12_2_00007FFD656A26F8 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656751C0 | 12_2_00007FFD656751C0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A01C4 | 12_2_00007FFD656A01C4 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656601B0 | 12_2_00007FFD656601B0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65688190 | 12_2_00007FFD65688190 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565E230 | 12_2_00007FFD6565E230 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569F230 | 12_2_00007FFD6569F230 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565C200 | 12_2_00007FFD6565C200 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656520D0 | 12_2_00007FFD656520D0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65685070 | 12_2_00007FFD65685070 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6568E070 | 12_2_00007FFD6568E070 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565B150 | 12_2_00007FFD6565B150 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569F124 | 12_2_00007FFD6569F124 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565E100 | 12_2_00007FFD6565E100 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A03D0 | 12_2_00007FFD656A03D0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656AF394 | 12_2_00007FFD656AF394 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65666380 | 12_2_00007FFD65666380 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65655380 | 12_2_00007FFD65655380 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65670370 | 12_2_00007FFD65670370 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A2374 | 12_2_00007FFD656A2374 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569F448 | 12_2_00007FFD6569F448 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65684420 | 12_2_00007FFD65684420 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A42BC | 12_2_00007FFD656A42BC |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65664270 | 12_2_00007FFD65664270 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65663350 | 12_2_00007FFD65663350 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569F33C | 12_2_00007FFD6569F33C |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6568E310 | 12_2_00007FFD6568E310 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656AB308 | 12_2_00007FFD656AB308 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656522F0 | 12_2_00007FFD656522F0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65687D80 | 12_2_00007FFD65687D80 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6566FE40 | 12_2_00007FFD6566FE40 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A0E4C | 12_2_00007FFD656A0E4C |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569EE04 | 12_2_00007FFD6569EE04 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65686DE0 | 12_2_00007FFD65686DE0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6566CCB0 | 12_2_00007FFD6566CCB0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656B5C8C | 12_2_00007FFD656B5C8C |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656AAC6C | 12_2_00007FFD656AAC6C |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6568DD30 | 12_2_00007FFD6568DD30 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656AED14 | 12_2_00007FFD656AED14 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6568BD00 | 12_2_00007FFD6568BD00 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569ECF8 | 12_2_00007FFD6569ECF8 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65684CE0 | 12_2_00007FFD65684CE0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A1FDC | 12_2_00007FFD656A1FDC |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65662FD0 | 12_2_00007FFD65662FD0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569FFC0 | 12_2_00007FFD6569FFC0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565BFA0 | 12_2_00007FFD6565BFA0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565EF90 | 12_2_00007FFD6565EF90 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6566CF80 | 12_2_00007FFD6566CF80 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65652F60 | 12_2_00007FFD65652F60 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A1058 | 12_2_00007FFD656A1058 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569F01C | 12_2_00007FFD6569F01C |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A4FE8 | 12_2_00007FFD656A4FE8 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A3E84 | 12_2_00007FFD656A3E84 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65656F20 | 12_2_00007FFD65656F20 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569EF10 | 12_2_00007FFD6569EF10 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65653EF0 | 12_2_00007FFD65653EF0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A0A14 | 12_2_00007FFD656A0A14 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65663880 | 12_2_00007FFD65663880 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656AE880 | 12_2_00007FFD656AE880 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656B3948 | 12_2_00007FFD656B3948 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65666930 | 12_2_00007FFD65666930 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65664900 | 12_2_00007FFD65664900 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656ACBAC | 12_2_00007FFD656ACBAC |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A4B84 | 12_2_00007FFD656A4B84 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656A0C48 | 12_2_00007FFD656A0C48 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65662C20 | 12_2_00007FFD65662C20 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565FBE0 | 12_2_00007FFD6565FBE0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569EBEC | 12_2_00007FFD6569EBEC |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6565CAC0 | 12_2_00007FFD6565CAC0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65659AA0 | 12_2_00007FFD65659AA0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD656B9A98 | 12_2_00007FFD656B9A98 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65665B50 | 12_2_00007FFD65665B50 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65657B50 | 12_2_00007FFD65657B50 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65651B20 | 12_2_00007FFD65651B20 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD65670AE0 | 12_2_00007FFD65670AE0 |
Source: C:\Windows\explorer.exe | Code function: 12_2_00007FFD6569EAE0 | 12_2_00007FFD6569EAE0 |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: cfgmgr32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: virtdisk.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: smartscreenps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: shdocvw.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: servicingcommon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ep_setup.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\sc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\sc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: webview2loader.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.fileexplorer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winuicohabitation.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.pcshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.hardwareconfirmator.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: profext.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: stobject.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pnidui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: inputswitch.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowsudk.shellcommon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: peopleband.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ninput.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpnapps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.fileexplorer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winuicohabitation.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.pcshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.hardwareconfirmator.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: profext.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: stobject.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pnidui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: inputswitch.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowsudk.shellcommon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: peopleband.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ninput.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpnapps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cfgmgr32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mrmcorer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: usermgrcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.applicationmodel.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appxdeploymentclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: languageoverlayutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: usermgrproxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bcp47mrm.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.cloudstore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositoryclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: idstore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appextension.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wlidprov.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.cloudstore.schema.shell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositorycore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sndvolsso.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.immersive.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: tiledatarepository.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: staterepository.core.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepository.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.immersiveshell.serviceprovider.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: deviceassociation.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cldapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: fltlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: thumbcache.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: applicationframe.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.shellcommon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: activationclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: photometadatahandler.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.fileexplorer.common.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.web.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.system.launcher.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: container.policy.manager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: holographicextensions.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: abovelockapphost.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pfclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.core.textinput.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.shell.bluelightreduction.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.signals.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: directxdatabasehelper.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mfplat.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rtworkq.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ehstorshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cscui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: actxprxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cdp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.gaming.input.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.ui.shell.windowtabmanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: notificationcontrollerps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.networking.connectivity.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pcshellcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: settingshandlers_desktoptaskbar.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: systemsettings.datamodel.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.accessibility.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: switcherdatamodel.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: structuredquery.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.search.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptngc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dmenrollengine.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cflapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.security.authentication.web.core.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: daxexec.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: container.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: shellcommoncommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winbio.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cloudexperiencehostredirection.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: clipc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msvcp140_app.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140_1_app.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140_app.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140_app.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140_1_app.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140_app.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.management.inprocobjects.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: npmproxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msxml6.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: capabilityaccessmanagerclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: batmeter.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.shell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wmiclnt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: prnfldr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: es.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uianimation.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpnclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.globalization.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.media.devices.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: syncreg.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: actioncenter.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dusmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpdshserviceobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: portabledevicetypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: portabledeviceapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cscobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: srchadmin.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: shdocvw.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: synccenter.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: imapi2.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: audioses.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netprofm.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: networkuxbroker.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ethernetmediamanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dot3api.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mobilenetworking.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wlanapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncsi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wcmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: microsoft.internal.frameworkudk.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: microsoft.ui.windowing.core.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: microsoft.internal.frameworkudk.system.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mrm.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bluetoothapis.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: marshal.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmcorei.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: microsoft.ui.composition.ossupport.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3dcompiler_47.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: marshal.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: microsoft.inputstatemanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: microsoft.ui.input.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: themecpl.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: duser.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dlnashext.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpdshext.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: microsoft.directmanipulation.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.energy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: microsoft.ui.xaml.internal.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: threadpoolwinrt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wscinterop.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wscapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: werconcpl.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: diagnosticdatasettings.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: hcproviders.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wevtapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ieproxy.dll | Jump to behavior |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: vcruntime140_1_app.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: vcruntime140_app.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: vcruntime140_app.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: widgetboardview.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: msvcp140_app.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: d2d1.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: dwmapi.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: windows.staterepositorycore.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: windows.staterepositoryclient.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: userenv.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: xmllite.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: powrprof.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: powrprof.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: rometadata.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: umpdc.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: execmodelclient.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: windows.shell.servicehostbuilder.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: execmodelproxy.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: windowsudk.shellcommon.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: appxdeploymentclient.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: capauthz.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: ntmarta.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: shellcommoncommonproxystub.dll | |
Source: C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.30502.30.0_x64__cw5n1h2txyewy\WidgetBoard.exe | Section loaded: coremessaging.dll | |