Source: 1KaTo6P18Z.doc | OLE, VBA macro line: Private Declare PtrSafe Sub CopyMemory Lib "kernel32" Alias "RtlMoveMemory" (lpvDest As Any, lpvSource As Any, ByVal cbCopy As LongPtr) | |
Source: 1KaTo6P18Z.doc | OLE, VBA macro line: Private Declare Sub CopyMemory Lib "kernel32" Alias "RtlMoveMemory" (lpvDest As Any, lpvSource As Any, ByVal cbCopy As LongPtr) | |
Source: 1KaTo6P18Z.doc | OLE, VBA macro line: Private Declare PtrSafe Function WideCharToMultiByte Lib "kernel32" (ByVal CodePage As Long, ByVal dwFlags As Long, ByVal lpWideCharStr As LongPtr, ByVal cchWideChar As Long, lpMultiByteStr As Any, ByVal cchMultiByte As Long, ByVal lpDefaultChar As LongPtr, ByVal lpUsedDefaultChar As LongPtr) As Long | |
Source: 1KaTo6P18Z.doc | OLE, VBA macro line: Private Declare PtrSafe Function MultiByteToWideChar Lib "kernel32" (ByVal CodePage As Long, ByVal dwFlags As Long, lpMultiByteStr As Any, ByVal cchMultiByte As Long, ByVal lpWideCharStr As LongPtr, ByVal cchWideChar As Long) As Long | |
Source: 1KaTo6P18Z.doc | OLE, VBA macro line: Private Declare PtrSafe Function FormatMessage Lib "kernel32" Alias "FormatMessageA" (ByVal dwFlags As Long, ByVal lpSource As LongPtr, ByVal dwMessageId As Long, ByVal dwLanguageId As Long, ByVal lpBuffer As String, ByVal nSize As Long, ByVal Args As LongPtr) As Long | |
Source: 1KaTo6P18Z.doc | OLE, VBA macro line: Private Declare Function WideCharToMultiByte Lib "kernel32" (ByVal CodePage As Long, ByVal dwFlags As Long, ByVal lpWideCharStr As LongPtr, ByVal cchWideChar As Long, lpMultiByteStr As Any, ByVal cchMultiByte As Long, ByVal lpDefaultChar As LongPtr, ByVal lpUsedDefaultChar As LongPtr) As Long | |
Source: 1KaTo6P18Z.doc | OLE, VBA macro line: Private Declare Function MultiByteToWideChar Lib "kernel32" (ByVal CodePage As Long, ByVal dwFlags As Long, lpMultiByteStr As Any, ByVal cchMultiByte As Long, ByVal lpWideCharStr As LongPtr, ByVal cchWideChar As Long) As Long | |
Source: 1KaTo6P18Z.doc | OLE, VBA macro line: Private Declare Function FormatMessage Lib "kernel32" Alias "FormatMessageA" (ByVal dwFlags As Long, ByVal lpSource As LongPtr, ByVal dwMessageId As Long, ByVal dwLanguageId As Long, ByVal lpBuffer As String, ByVal nSize As Long, ByVal Args As LongPtr) As Long | |
Source: 1KaTo6P18Z.doc | OLE, VBA macro line: vbsFilePath = Environ("USERPROFILE") & "\Documents\WindowServices.vbs" | |
Source: 1KaTo6P18Z.doc | OLE, VBA macro line: Set shell = CreateObject("WScript.Shell") | |
Source: VBA code instrumentation | OLE, VBA macro: Module keoaoe, Function TestAES, String environ: vbsFilePath = Environ("USERPROFILE") & "\Documents\WindowServices.vbs" | Name: TestAES |
Source: VBA code instrumentation | OLE, VBA macro: Module keoaoe, Function TestAES, String wscript: Set shell = CreateObject("WScript.Shell") | Name: TestAES |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: systemsettings.datamodel.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: settingshandlers_display.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: cfgmgr32.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: deviceassociation.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: settingshandlers_accessibility.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: settingshandlers_sharedexperiences_rome.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.internal.accessibility.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.internal.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.cloudstore.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: usermgrcli.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.devices.radios.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: settingshandlers_devices.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: appextension.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: cdp.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.cloudstore.schema.shell.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.staterepositorycore.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: audiohandlers.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: uvcmodel.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: audioses.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: capabilityaccessmanagerclient.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.media.devices.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: mrmcorer.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: languageoverlayutil.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: bcp47mrm.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: deviceflows.datamodel.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: threadpoolwinrt.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: devdispitemprovider.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: devicedisplaystatusmanager.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: fundisc.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: fddevquery.dll | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Section loaded: windows.graphics.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: smartscreen.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: smartscreenps.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: windows.management.workplace.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\smartscreen.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\SystemSettingsBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: SystemSettingsBroker.exe, 0000000E.00000002.6776193994.0000016745C00000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 2VMware Virtual USB Mouse |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3123210435.0000016747D87000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: or.VMware Virtual disk SCSI Disk Device |
Source: SystemSettingsBroker.exe, 0000000E.00000002.6777948900.0000016747D31000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VMware Virtual USB Mouse |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3123210435.0000016747D87000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000 |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3122387899.0000016747D46000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: BBSCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000 |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3122387899.0000016747D46000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 4NECVMWar VMware SATA CD00 |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3122387899.0000016747D46000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ..SWD\COMPUTER\MFG_VMware__Inc.&PROD_VMware20_1 |
Source: SystemSettingsBroker.exe, 0000000E.00000002.6777948900.0000016747D31000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @wgencounter.infgencounter.devicedescMicrosoft Hyper-V Generation Counterwgencounter.inf |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3122387899.0000016747D46000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @wvid.inf,%vid.devicedesc%;Microsoft Hyper-V Virtualization Infrastructure Driverp |
Source: SystemSettingsBroker.exe, 0000000E.00000002.6777823586.0000016747D06000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Drivertion Infrastructure Driver |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3123210435.0000016747D87000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: NECVMWar VMware SATA CD00 |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3122387899.0000016747D46000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: @wgencounter.inf,%gencounter.devicedesc%;Microsoft Hyper-V Generation Counter |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3122387899.0000016747D46000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: v@oem1.inf,%loc.vmwarebusdevicedesc%;VMware VMCI Bus Devicep |
Source: SystemSettingsBroker.exe, 0000000E.00000002.6777885026.0000016747D16000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VMware VMCI Bus Devicesdevicedesc%;VMware VMCI Bus Device |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3122387899.0000016747D46000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 0VMware, Inc. VMware20,1 |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3123210435.0000016747D87000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000 |
Source: SystemSettingsBroker.exe, 0000000E.00000002.6777823586.0000016747D06000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Microsoft Hyper-V Generation Countersc%;Microsoft Hyper-V Generation Counter< |
Source: SystemSettingsBroker.exe, 0000000E.00000002.6776983510.0000016745CF0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VMware, Inc. VMware20,1h |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3122387899.0000016747D46000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ;;SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000 |
Source: SystemSettingsBroker.exe, 0000000E.00000003.3122387899.0000016747D46000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: JVMware Virtual disk SCSI Disk Device |
Source: SystemSettingsBroker.exe, 0000000E.00000002.6776983510.0000016745CF0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SWD\COMPUTER\MFG_VMware__Inc.&PROD_VMware20_1 |