Source: unknown | Process created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\Drivespan.dll" | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",#1 | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Drivespan.dll,EntryPointProc | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",#1 | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Drivespan.dll,eQ8FKAFK298HGKAF0PK1K0RFJF9OMG9348 | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Drivespan.dll,ru3n | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",EntryPointProc | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",eQ8FKAFK298HGKAF0PK1K0RFJF9OMG9348 | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",ru3n | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",rusn | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",run | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",#1 | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Drivespan.dll,EntryPointProc | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Drivespan.dll,eQ8FKAFK298HGKAF0PK1K0RFJF9OMG9348 | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Drivespan.dll,ru3n | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",EntryPointProc | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",eQ8FKAFK298HGKAF0PK1K0RFJF9OMG9348 | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",ru3n | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",rusn | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",run | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Drivespan.dll",#1 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\cttune.exe "C:\Windows\SysWOW64\cttune.exe" | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Section loaded: msvcp140.dll | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: magnification.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: d3d9.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: security.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: idndl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: winhttpcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: duser.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: magnification.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: d3d9.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: security.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: duser.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: duser.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: duser.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cttune.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 45E0000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 45E1000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4969000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 496C000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 497A000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4981000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4985000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4986000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4987000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4988000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 49DD000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4A00000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4A00018 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AAF0000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AAF1000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AE79000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AE7C000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AE8A000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AE91000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AE95000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AE96000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AE97000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AE98000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: AEED000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 52E0000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 52E0018 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5890000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5891000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5C19000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5C1C000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5C2A000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5C31000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5C35000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5C36000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5C37000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5C38000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5C8D000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 2F10000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 2F10018 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4ED0000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4ED1000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5259000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 525C000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 526A000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5271000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5275000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5276000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5277000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5278000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 52CD000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5300000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 5300018 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4A20000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4A21000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4DA9000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4DAC000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4DBA000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4DC1000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4DC5000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4DC6000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4DC7000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4DC8000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 4E1D000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 44C0000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 44C0018 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 2F20000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 2F21000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 32A9000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 32AC000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 32BA000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 32C1000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 32C5000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 32C6000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 32C7000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 32C8000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 331D000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 3340000 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Memory written: C:\Windows\SysWOW64\cttune.exe base: 3340018 | Jump to behavior |