Source: C:\Users\user\Desktop\7q551ugrWe.exe | Code function: 0_2_00403387 GetFileAttributesW,SetLastError,FindFirstFileW,FindClose,CompareFileTime, | 0_2_00403387 |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Code function: 0_2_00402EE6 FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z, | 0_2_00402EE6 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C5910 GetModuleFileNameA,FindFirstFileA,SendMessageA,FindNextFileA,FindClose, | 22_2_00007FF67E7C5910 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E6DD1 OpenInputDesktop,CloseDesktop,GetTickCount,GetLogicalDriveStringsA,GetDriveTypeA,SHGetMalloc,SHGetSpecialFolderLocation,SHGetPathFromIDListA,SetErrorMode,FindFirstFileA,SetErrorMode,lstrlenA,FindNextFileA,FindClose,LeaveCriticalSection, | 22_2_00007FF67E7E6DD1 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7EC210 SetErrorMode,FindFirstFileA,SetErrorMode,FindClose, | 22_2_00007FF67E7EC210 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E87A228 __doserrno,_errno,_invalid_parameter_noinfo,_errno,__doserrno,_getdrive,FindFirstFileExA,_errno,_errno,_errno,_errno,_errno,GetDriveTypeA,free,free,_errno,__doserrno,_wsopen_s,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, | 22_2_00007FF67E87A228 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C5910 GetModuleFileNameA,FindFirstFileA,SendMessageA,FindNextFileA,FindClose, | 25_2_00007FF67E7C5910 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E6DD1 OpenInputDesktop,CloseDesktop,GetTickCount,GetLogicalDriveStringsA,GetDriveTypeA,SHGetMalloc,SHGetSpecialFolderLocation,SHGetPathFromIDListA,SetErrorMode,FindFirstFileA,SetErrorMode,lstrlenA,FindNextFileA,FindClose,LeaveCriticalSection, | 25_2_00007FF67E7E6DD1 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7EC210 SetErrorMode,FindFirstFileA,SetErrorMode,FindClose, | 25_2_00007FF67E7EC210 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E87A228 __doserrno,_errno,_invalid_parameter_noinfo,_errno,__doserrno,_getdrive,FindFirstFileExA,_errno,_errno,_errno,_errno,_errno,GetDriveTypeA,free,free,_errno,__doserrno,_wsopen_s,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, | 25_2_00007FF67E87A228 |
Source: 7q551ugrWe.exe, 00000000.00000003.1349858008.0000000000999000.00000004.00001000.00020000.00000000.sdmp, 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002969000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: 77EC63BDA74BD0D0E0426DC8F80085060.11.dr | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002790000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe, 00000016.00000000.1454823305.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000016.00000002.3193682358.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000000.1534378586.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000002.1537363283.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://forum.uvnc.com |
Source: 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002790000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe, 00000016.00000000.1454823305.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000016.00000002.3193682358.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000000.1534378586.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000002.1537363283.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://java.sun.com/products/plugin/index.html#download |
Source: 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002790000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe, 00000016.00000000.1454823305.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000016.00000002.3193682358.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000000.1534378586.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000002.1537363283.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://java.sun.com/update/1.4.2/jinstall-1_4-windows-i586.cab#Version=1 |
Source: 7q551ugrWe.exe, 00000000.00000003.1349858008.0000000000999000.00000004.00001000.00020000.00000000.sdmp, 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002969000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: 7q551ugrWe.exe, 00000000.00000003.1349858008.0000000000999000.00000004.00001000.00020000.00000000.sdmp, 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002969000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: 7q551ugrWe.exe, 00000000.00000003.1349858008.0000000000999000.00000004.00001000.00020000.00000000.sdmp, 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002969000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: 7q551ugrWe.exe, 00000000.00000003.1349858008.0000000000999000.00000004.00001000.00020000.00000000.sdmp, 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002969000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: 7q551ugrWe.exe, 00000000.00000003.1349581148.000000000295B000.00000004.00000020.00020000.00000000.sdmp, 7q551ugrWe.exe, 00000000.00000003.1349858008.000000000098B000.00000004.00001000.00020000.00000000.sdmp, 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002790000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe, 00000016.00000000.1454915020.00007FF67EA3C000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000016.00000000.1454823305.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000016.00000002.3193682358.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000002.1537485169.00007FF67EA3C000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000000.1534378586.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000002.1537363283.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://www.uvnc.com |
Source: 7q551ugrWe.exe, 00000000.00000003.1349581148.0000000002790000.00000004.00000020.00020000.00000000.sdmp, sync_browser.exe, 00000016.00000000.1454823305.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000016.00000002.3193682358.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000000.1534378586.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe, 00000019.00000002.1537363283.00007FF67E899000.00000002.00000001.01000000.00000007.sdmp, sync_browser.exe.6.dr, WPSela.LSZr7V.2.dr, WPSela.LSZr7V.0.dr | String found in binary or memory: http://www.uvnc.comopenhttp://forum.uvnc.comnet |
Source: 2D85F72862B55C4EADD9E66E06947F3D0.11.dr | String found in binary or memory: http://x1.i.lencr.org/ |
Source: ReaderMessages.9.dr | String found in binary or memory: https://www.adobe.co |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C1DD0 OpenClipboard,EmptyClipboard,CloseClipboard,MultiByteToWideChar,GlobalAlloc,GlobalLock,MultiByteToWideChar,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard,GlobalAlloc,CloseClipboard,GlobalLock,GlobalUnlock,SetClipboardData,GlobalFree,GlobalAlloc,CloseClipboard,GlobalLock,GlobalUnlock,SetClipboardData,GlobalFree,GlobalAlloc,CloseClipboard,GlobalLock,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard, | 22_2_00007FF67E7C1DD0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7F13A0 OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,SetClipboardData,CloseClipboard, | 22_2_00007FF67E7F13A0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C1DD0 OpenClipboard,EmptyClipboard,CloseClipboard,MultiByteToWideChar,GlobalAlloc,GlobalLock,MultiByteToWideChar,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard,GlobalAlloc,CloseClipboard,GlobalLock,GlobalUnlock,SetClipboardData,GlobalFree,GlobalAlloc,CloseClipboard,GlobalLock,GlobalUnlock,SetClipboardData,GlobalFree,GlobalAlloc,CloseClipboard,GlobalLock,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard, | 25_2_00007FF67E7C1DD0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7F13A0 OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,SetClipboardData,CloseClipboard, | 25_2_00007FF67E7F13A0 |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Code function: 0_2_00405721 | 0_2_00405721 |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Code function: 0_2_004139D1 | 0_2_004139D1 |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Code function: 0_2_00413AAB | 0_2_00413AAB |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Code function: 0_2_00413370 | 0_2_00413370 |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Code function: 0_2_00413D43 | 0_2_00413D43 |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Code function: 0_2_0040AD30 | 0_2_0040AD30 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E36D0 | 22_2_00007FF67E7E36D0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D0270 | 22_2_00007FF67E7D0270 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7CC810 | 22_2_00007FF67E7CC810 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D9740 | 22_2_00007FF67E7D9740 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DAF60 | 22_2_00007FF67E7DAF60 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C3770 | 22_2_00007FF67E7C3770 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7EE780 | 22_2_00007FF67E7EE780 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E87DF80 | 22_2_00007FF67E87DF80 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DC8D0 | 22_2_00007FF67E7DC8D0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D20E0 | 22_2_00007FF67E7D20E0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D1100 | 22_2_00007FF67E7D1100 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7CA910 | 22_2_00007FF67E7CA910 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D6930 | 22_2_00007FF67E7D6930 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DA130 | 22_2_00007FF67E7DA130 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7EA870 | 22_2_00007FF67E7EA870 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C1880 | 22_2_00007FF67E7C1880 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DA890 | 22_2_00007FF67E7DA890 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DC090 | 22_2_00007FF67E7DC090 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D70B0 | 22_2_00007FF67E7D70B0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C1DD0 | 22_2_00007FF67E7C1DD0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E6DD1 | 22_2_00007FF67E7E6DD1 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D8E10 | 22_2_00007FF67E7D8E10 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DE610 | 22_2_00007FF67E7DE610 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7F3E20 | 22_2_00007FF67E7F3E20 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E1620 | 22_2_00007FF67E7E1620 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E4D7E | 22_2_00007FF67E7E4D7E |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D8590 | 22_2_00007FF67E7D8590 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DC5B0 | 22_2_00007FF67E7DC5B0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E810650 | 22_2_00007FF67E810650 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E2650 | 22_2_00007FF67E7E2650 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7F1660 | 22_2_00007FF67E7F1660 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7EAE70 | 22_2_00007FF67E7EAE70 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E88068C | 22_2_00007FF67E88068C |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C4E80 | 22_2_00007FF67E7C4E80 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E6BBD | 22_2_00007FF67E7E6BBD |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DB3D0 | 22_2_00007FF67E7DB3D0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C7BE2 | 22_2_00007FF67E7C7BE2 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D93E0 | 22_2_00007FF67E7D93E0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D4C10 | 22_2_00007FF67E7D4C10 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E87E400 | 22_2_00007FF67E87E400 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7EA420 | 22_2_00007FF67E7EA420 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C7B37 | 22_2_00007FF67E7C7B37 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C7B71 | 22_2_00007FF67E7C7B71 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DBB80 | 22_2_00007FF67E7DBB80 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C4390 | 22_2_00007FF67E7C4390 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D7B90 | 22_2_00007FF67E7D7B90 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E739B | 22_2_00007FF67E7E739B |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C7BA6 | 22_2_00007FF67E7C7BA6 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E2CC0 | 22_2_00007FF67E7E2CC0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7F1CE0 | 22_2_00007FF67E7F1CE0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7EDCF0 | 22_2_00007FF67E7EDCF0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7CDCF0 | 22_2_00007FF67E7CDCF0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D1D10 | 22_2_00007FF67E7D1D10 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7DAD30 | 22_2_00007FF67E7DAD30 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7F3460 | 22_2_00007FF67E7F3460 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E882C70 | 22_2_00007FF67E882C70 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E888C90 | 22_2_00007FF67E888C90 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7F54A0 | 22_2_00007FF67E7F54A0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7F5CA0 | 22_2_00007FF67E7F5CA0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E51B7 | 22_2_00007FF67E7E51B7 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7CE1D0 | 22_2_00007FF67E7CE1D0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E8809F0 | 22_2_00007FF67E8809F0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C79E9 | 22_2_00007FF67E7C79E9 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C4200 | 22_2_00007FF67E7C4200 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C7A1C | 22_2_00007FF67E7C7A1C |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E5A33 | 22_2_00007FF67E7E5A33 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7ED150 | 22_2_00007FF67E7ED150 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C5170 | 22_2_00007FF67E7C5170 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7EF980 | 22_2_00007FF67E7EF980 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7D8980 | 22_2_00007FF67E7D8980 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C81AD | 22_2_00007FF67E7C81AD |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7EC2C0 | 22_2_00007FF67E7EC2C0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C7ACF | 22_2_00007FF67E7C7ACF |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E8312C0 | 22_2_00007FF67E8312C0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C7B04 | 22_2_00007FF67E7C7B04 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7EAB10 | 22_2_00007FF67E7EAB10 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7F0330 | 22_2_00007FF67E7F0330 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E623E | 22_2_00007FF67E7E623E |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E877250 | 22_2_00007FF67E877250 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C7A5B | 22_2_00007FF67E7C7A5B |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C2270 | 22_2_00007FF67E7C2270 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7E8A70 | 22_2_00007FF67E7E8A70 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C3A90 | 22_2_00007FF67E7C3A90 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7C7A9A | 22_2_00007FF67E7C7A9A |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7CC810 | 25_2_00007FF67E7CC810 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D9740 | 25_2_00007FF67E7D9740 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DAF60 | 25_2_00007FF67E7DAF60 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C3770 | 25_2_00007FF67E7C3770 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7EE780 | 25_2_00007FF67E7EE780 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E87DF80 | 25_2_00007FF67E87DF80 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DC8D0 | 25_2_00007FF67E7DC8D0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D20E0 | 25_2_00007FF67E7D20E0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D1100 | 25_2_00007FF67E7D1100 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7CA910 | 25_2_00007FF67E7CA910 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D6930 | 25_2_00007FF67E7D6930 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DA130 | 25_2_00007FF67E7DA130 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7EA870 | 25_2_00007FF67E7EA870 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C1880 | 25_2_00007FF67E7C1880 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DA890 | 25_2_00007FF67E7DA890 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DC090 | 25_2_00007FF67E7DC090 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D70B0 | 25_2_00007FF67E7D70B0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C1DD0 | 25_2_00007FF67E7C1DD0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E6DD1 | 25_2_00007FF67E7E6DD1 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E2DF3 | 25_2_00007FF67E7E2DF3 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D8E10 | 25_2_00007FF67E7D8E10 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DE610 | 25_2_00007FF67E7DE610 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7F3E20 | 25_2_00007FF67E7F3E20 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E1620 | 25_2_00007FF67E7E1620 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E4D7E | 25_2_00007FF67E7E4D7E |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D8590 | 25_2_00007FF67E7D8590 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DC5B0 | 25_2_00007FF67E7DC5B0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E36D0 | 25_2_00007FF67E7E36D0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E810650 | 25_2_00007FF67E810650 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E2650 | 25_2_00007FF67E7E2650 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7F1660 | 25_2_00007FF67E7F1660 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7EAE70 | 25_2_00007FF67E7EAE70 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E88068C | 25_2_00007FF67E88068C |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C4E80 | 25_2_00007FF67E7C4E80 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E6BBD | 25_2_00007FF67E7E6BBD |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DB3D0 | 25_2_00007FF67E7DB3D0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C7BE2 | 25_2_00007FF67E7C7BE2 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D93E0 | 25_2_00007FF67E7D93E0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D4C10 | 25_2_00007FF67E7D4C10 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E87E400 | 25_2_00007FF67E87E400 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7EA420 | 25_2_00007FF67E7EA420 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C7B37 | 25_2_00007FF67E7C7B37 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C7B71 | 25_2_00007FF67E7C7B71 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DBB80 | 25_2_00007FF67E7DBB80 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C4390 | 25_2_00007FF67E7C4390 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D7B90 | 25_2_00007FF67E7D7B90 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E739B | 25_2_00007FF67E7E739B |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C7BA6 | 25_2_00007FF67E7C7BA6 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7F1CE0 | 25_2_00007FF67E7F1CE0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7EDCF0 | 25_2_00007FF67E7EDCF0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7CDCF0 | 25_2_00007FF67E7CDCF0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D1D10 | 25_2_00007FF67E7D1D10 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7DAD30 | 25_2_00007FF67E7DAD30 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7F3460 | 25_2_00007FF67E7F3460 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E882C70 | 25_2_00007FF67E882C70 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E888C90 | 25_2_00007FF67E888C90 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7F54A0 | 25_2_00007FF67E7F54A0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7F5CA0 | 25_2_00007FF67E7F5CA0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E51B7 | 25_2_00007FF67E7E51B7 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7CE1D0 | 25_2_00007FF67E7CE1D0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E8809F0 | 25_2_00007FF67E8809F0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C79E9 | 25_2_00007FF67E7C79E9 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C4200 | 25_2_00007FF67E7C4200 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C7A1C | 25_2_00007FF67E7C7A1C |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E5A33 | 25_2_00007FF67E7E5A33 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7ED150 | 25_2_00007FF67E7ED150 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C5170 | 25_2_00007FF67E7C5170 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7EF980 | 25_2_00007FF67E7EF980 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D8980 | 25_2_00007FF67E7D8980 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C81AD | 25_2_00007FF67E7C81AD |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7EC2C0 | 25_2_00007FF67E7EC2C0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C7ACF | 25_2_00007FF67E7C7ACF |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E8312C0 | 25_2_00007FF67E8312C0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C7B04 | 25_2_00007FF67E7C7B04 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7EAB10 | 25_2_00007FF67E7EAB10 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7F0330 | 25_2_00007FF67E7F0330 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E623E | 25_2_00007FF67E7E623E |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E877250 | 25_2_00007FF67E877250 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C7A5B | 25_2_00007FF67E7C7A5B |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C2270 | 25_2_00007FF67E7C2270 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7E8A70 | 25_2_00007FF67E7E8A70 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7D0270 | 25_2_00007FF67E7D0270 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C3A90 | 25_2_00007FF67E7C3A90 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 25_2_00007FF67E7C7A9A | 25_2_00007FF67E7C7A9A |
Source: unknown | Process created: C:\Users\user\Desktop\7q551ugrWe.exe "C:\Users\user\Desktop\7q551ugrWe.exe" | |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy /y "%CD%\*.*" "%CD%\..\..\..\..\..\..\Windows\Tasks\" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & copy 0271695705143540 0271695705143540.cmd | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & 0271695705143540.cmd | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Downloads\Lom.pdf" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /f /im sync_browser.exe | |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2088 --field-trial-handle=1724,i,3112944997856603396,2159099869268149404,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\sync_browser.exe C:\Windows\Tasks\sync_browser.exe | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 8 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\sync_browser.exe C:\Windows\Tasks\sync_browser.exe -autoreconnect -id:user-PC_VPANJC -connect tbdcic.info:443 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 4 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 42 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 42 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 42 | |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy /y "%CD%\*.*" "%CD%\..\..\..\..\..\..\Windows\Tasks\" | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & copy 0271695705143540 0271695705143540.cmd | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & 0271695705143540.cmd | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Downloads\Lom.pdf" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /f /im sync_browser.exe | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\sync_browser.exe C:\Windows\Tasks\sync_browser.exe | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 8 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\sync_browser.exe C:\Windows\Tasks\sync_browser.exe -autoreconnect -id:user-PC_VPANJC -connect tbdcic.info:443 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 4 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 42 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 42 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 8 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 42 | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2088 --field-trial-handle=1724,i,3112944997856603396,2159099869268149404,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\7q551ugrWe.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: winmm.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: userenv.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: winsta.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: wldp.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: msls31.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: winmm.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: userenv.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: rasadhlp.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E8177F0 GetPrivateProfileIntA,RegQueryValueExA,GetPrivateProfileIntA, | 22_2_00007FF67E8177F0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E817750 GetPrivateProfileIntA,RegCloseKey,RegCloseKey,RegCloseKey, | 22_2_00007FF67E817750 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E817F50 GetPrivateProfileIntA, | 22_2_00007FF67E817F50 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E8178E0 GetPrivateProfileIntA,RegQueryValueExA,RegQueryValueExA,GetPrivateProfileStringA, | 22_2_00007FF67E8178E0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E817E10 GetPrivateProfileIntA, | 22_2_00007FF67E817E10 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E817D50 GetPrivateProfileIntA, | 22_2_00007FF67E817D50 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E817650 GetPrivateProfileIntA,RegCreateKeyExA,RegCreateKeyExA, | 22_2_00007FF67E817650 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E817EB0 GetPrivateProfileIntA, | 22_2_00007FF67E817EB0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E817BD0 GetPrivateProfileIntA, | 22_2_00007FF67E817BD0 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E817C90 GetPrivateProfileIntA, | 22_2_00007FF67E817C90 |
Source: C:\Windows\Tasks\sync_browser.exe | Code function: 22_2_00007FF67E7CE1D0 GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,GetLastError,_itow,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileStringA,GetPrivateProfileStringA,GetPrivateProfileStringA,WritePrivateProfileStringA,WritePrivateProfileStringA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileStringA,GetPrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,WritePrivateProfileStringA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileStringA,GetPrivateProfileStringA,WritePrivateProfileStringA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA, |