Source: | Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb source: createdump.exe, 00000008.00000002.2309946294.00007FF7C76D8000.00000002.00000001.01000000.00000006.sdmp, createdump.exe, 00000008.00000000.2304497963.00007FF7C76D8000.00000002.00000001.01000000.00000006.sdmp |
Source: | Binary string: C:\ReleaseAI\win\Release\bin\x86\embeddeduiproxy.pdb= source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\WinUiBootstrapperEui\WinUiBootstrapperEui.pdb)) source: K064a7Rfk7.msi |
Source: | Binary string: ucrtbase.pdb source: K064a7Rfk7.msi |
Source: | Binary string: api-ms-win-core-file-l1-2-0.pdb source: api-ms-win-core-file-l1-2-0.dll.2.dr |
Source: | Binary string: api-ms-win-core-memory-l1-1-0.pdb source: api-ms-win-core-memory-l1-1-0.dll.2.dr |
Source: | Binary string: api-ms-win-core-debug-l1-1-0.pdb source: api-ms-win-core-debug-l1-1-0.dll.2.dr |
Source: | Binary string: Microsoft.Web.WebView2.Core.pdbGCTL source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\custact\x86\SoftwareDetector.pdbm source: K064a7Rfk7.msi |
Source: | Binary string: E:\BA\201\s\140_release\vcrt_fwd_x86_release\Release\vcamp140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: K064a7Rfk7.msi |
Source: | Binary string: E:\BA\201\s\140_release\vcrt_fwd_x86_release\Release\vccorlib140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdbGCTL source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\WinUiBootstrapperEui\WinUiBootstrapperEui.pdb source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\stubs\x86\ExternalUi.pdb source: K064a7Rfk7.msi |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: api-ms-win-core-processthreads-l1-1-1.dll.2.dr |
Source: | Binary string: api-ms-win-core-heap-l1-1-0.pdb source: api-ms-win-core-heap-l1-1-0.dll.2.dr |
Source: | Binary string: D:\a\_work\1\s\140_release\vcrt_fwd_x86_release\Release\msvcp140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: api-ms-win-core-namedpipe-l1-1-0.dll.2.dr |
Source: | Binary string: D:\releases\dva\shared\adobe\utest\lib\win\release\64\utest.pdb source: utest.dll.2.dr |
Source: | Binary string: E:\BA\201\s\140_release\vcrt_fwd_x86_release\Release\vcomp140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\1\s\Win32\Release\Microsoft.Toolkit.Win32.UI.XamlApplication\Microsoft.Toolkit.Win32.UI.XamlHost.pdb!! source: K064a7Rfk7.msi |
Source: | Binary string: d:\a01\_work\12\s\\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: obs-ffmpeg-mux.exe, 00000007.00000002.2338386873.00007FFDAC131000.00000002.00000001.01000000.0000000C.sdmp, vcruntime140.dll.2.dr |
Source: | Binary string: D:\releases\dva\shared\adobe\utest\lib\win\release\64\utest.pdb((! source: utest.dll.2.dr |
Source: | Binary string: api-ms-win-core-file-l2-1-0.pdb source: api-ms-win-core-file-l2-1-0.dll.2.dr |
Source: | Binary string: C:\a\_work\1\s\BuildOutput\Release\x86\Microsoft.UI.Xaml\Microsoft.UI.Xaml.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\_work\1\s\140_release\vcrt_fwd_x86_release\Release\vcruntime140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: obs-ffmpeg-mux.pdb source: obs-ffmpeg-mux.exe, 00000007.00000002.2315346958.00007FF71E745000.00000002.00000001.01000000.00000005.sdmp, obs-ffmpeg-mux.exe, 00000007.00000000.2304470611.00007FF71E745000.00000002.00000001.01000000.00000005.sdmp |
Source: | Binary string: D:\a\1\s\Win32\Release\Microsoft.Toolkit.Win32.UI.XamlApplication\Microsoft.Toolkit.Win32.UI.XamlHost.pdb source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\bin\x86\embeddeduiproxy.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb;;;GCTL source: createdump.exe, 00000008.00000002.2309946294.00007FF7C76D8000.00000002.00000001.01000000.00000006.sdmp, createdump.exe, 00000008.00000000.2304497963.00007FF7C76D8000.00000002.00000001.01000000.00000006.sdmp |
Source: | Binary string: D:\a\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\Projects\WinRAR\rar\build\unrar64\Release\UnRAR.pdb source: UnRar.exe, 00000005.00000002.2303651093.00007FF7AAD08000.00000002.00000001.01000000.00000004.sdmp, UnRar.exe, 00000005.00000000.2292652385.00007FF7AAD08000.00000002.00000001.01000000.00000004.sdmp |
Source: | Binary string: C:\ReleaseAI\win\Release\custact\x86\SoftwareDetector.pdb source: K064a7Rfk7.msi |
Source: | Binary string: Microsoft.Web.WebView2.Core.pdb source: K064a7Rfk7.msi |
Source: | Binary string: ucrtbase.pdbUGP source: K064a7Rfk7.msi |
Source: | Binary string: api-ms-win-core-profile-l1-1-0.pdb source: api-ms-win-core-profile-l1-1-0.dll.2.dr |
Source: | Binary string: w32-pthreads.pdb source: obs-ffmpeg-mux.exe, 00000007.00000002.2338942242.00007FFDAC148000.00000002.00000001.01000000.0000000B.sdmp |
Source: | Binary string: C:\ReleaseAI\win\Release\custact\x86\AICustAct.pdb source: K064a7Rfk7.msi, MSIE1FA.tmp.2.dr, MSIE336.tmp.2.dr |
Source: | Binary string: D:\a\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdbGCTL source: K064a7Rfk7.msi |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACCCED8 FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn, | 5_2_00007FF7AACCCED8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACFF850 FindFirstFileExA, | 5_2_00007FF7AACFF850 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA378A430 TryEnterCriticalSection,TerminateThread,SetThreadpoolStackInformation,SetConsoleHistoryInfo,PrefetchVirtualMemory,GetQueuedCompletionStatusEx,SystemTimeToFileTime,GetExitCodeProcess,CreateSymbolicLinkTransactedW,FindFirstFileW,LoadModule,OpenFile,OpenThread,SetFileTime,WaitForThreadpoolWorkCallbacks,FreeLibraryAndExitThread,PowerCreateRequest,InterlockedPushListSListEx,LocalFileTimeToFileTime,FindCloseChangeNotification,CreateThreadpoolCleanupGroup,QueryFullProcessImageNameW,Wow64GetThreadSelectorEntry,IsValidNLSVersion,FreeLibraryAndExitThread,CreateEventExW,SetPriorityClass,IsValidNLSVersion,RegisterApplicationRecoveryCallback,GetFileSize,GlobalFree,GetFileMUIInfo,SetConsoleActiveScreenBuffer,LCIDToLocaleName, | 7_2_00007FFDA378A430 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3785730 SetFocus,CreateFileTransactedW,GetWindowContextHelpId,VirtualAlloc,FindNextVolumeMountPointW,OpenWaitableTimerW,FindNextStreamW,AddSIDToBoundaryDescriptor,EnterCriticalSection,DeleteSynchronizationBarrier,RemoveDirectoryTransactedW,LogicalToPhysicalPoint,OpenClipboard,SetWindowRgn,GetCommProperties,ShowCursor,GetFileBandwidthReservation,VirtualAlloc,GetProcessHeap,DeleteTimerQueueTimer,WriteTapemark,GlobalHandle,SetStdHandle,CreateTimerQueueTimer,GetProcessVersion,ReadConsoleOutputW,FindFirstFileW,GetProcessVersion,GetConsoleTitleW,HeapAlloc, | 7_2_00007FFDA3785730 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA37872D0 RegisterClassW,CreateWindowExW,ShowWindow,UpdateWindow,FindFirstFileW,FindClose,GetTempPathW,GetFileAttributesW,GetDC,CreateCompatibleBitmap,CreateCompatibleDC,SelectObject,CreateSolidBrush,FillRect,DeleteObject,GetObjectW,GetDIBits,SelectObject,DeleteDC,DeleteObject,CreateDirectoryW,type_info::_name_internal_method,GetMessageW,TranslateMessage,DispatchMessageW, | 7_2_00007FFDA37872D0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA38345D4 FindFirstFileExW, | 7_2_00007FFDA38345D4 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C12159 FindFirstFileExW, | 11_2_00C12159 |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: utest.dll.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0 |
Source: utest.dll.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0 |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: K064a7Rfk7.msi | String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0 |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: utest.dll.2.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0 |
Source: K064a7Rfk7.msi | String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0= |
Source: utest.dll.2.dr | String found in binary or memory: http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07 |
Source: K064a7Rfk7.msi | String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: utest.dll.2.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0 |
Source: utest.dll.2.dr | String found in binary or memory: http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K |
Source: K064a7Rfk7.msi | String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0K |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: obs-ffmpeg-mux.exe, obs-ffmpeg-mux.exe, 00000007.00000002.2316007345.00007FFD902DB000.00000002.00000001.01000000.0000000A.sdmp | String found in binary or memory: http://dashif.org/guidelines/trickmode |
Source: explorer.exe, 0000000B.00000002.2323519946.000000000076B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://kill-hit.com/Y |
Source: explorer.exe, 0000000B.00000002.2323519946.0000000000747000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://kill-hit.com/front.php?a=yrJh28ExgsVYO0Y&id=0 |
Source: explorer.exe, 0000000B.00000002.2323519946.000000000077F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://kill-hit.com/front.php?a=yrJh28ExgsVYO0Y&id=02Z |
Source: explorer.exe, 0000000B.00000002.2323519946.0000000000747000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://kill-hit.com/front.php?a=yrJh28ExgsVYO0Y&id=0S |
Source: explorer.exe, 0000000B.00000002.2323519946.000000000077F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://kill-hit.com:80/front.php?a=yrJh28ExgsVYO0Y&id=0 |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: utest.dll.2.dr | String found in binary or memory: http://ocsp.digicert.com0H |
Source: utest.dll.2.dr | String found in binary or memory: http://ocsp.digicert.com0I |
Source: K064a7Rfk7.msi | String found in binary or memory: http://ocsp.digicert.com0K |
Source: K064a7Rfk7.msi | String found in binary or memory: http://ocsp.digicert.com0N |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: http://ocsp.digicert.com0O |
Source: K064a7Rfk7.msi | String found in binary or memory: http://schemas.mic |
Source: obs-ffmpeg-mux.exe, 00000007.00000002.2316007345.00007FFD902DB000.00000002.00000001.01000000.0000000A.sdmp | String found in binary or memory: http://standards.iso.org/ittf/PubliclyAvailableStandards/MPEG-DASH_schema_files/DASH-MPD.xsd |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: utest.dll.2.dr | String found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0 |
Source: avcodec-60.dll.2.dr | String found in binary or memory: http://www.videolan.org/x264.html |
Source: K064a7Rfk7.msi | String found in binary or memory: https://aka.ms/winui2/webview2download/Reload(): |
Source: utest.dll.2.dr | String found in binary or memory: https://github.com/google/googletest/ |
Source: utest.dll.2.dr | String found in binary or memory: https://github.com/google/googletest/blob/master/googlemock/docs/CookBook.md#knowing-when-to-expect |
Source: classes.jsa.2.dr | String found in binary or memory: https://java.oracle.com/ |
Source: obs-ffmpeg-mux.exe, obs-ffmpeg-mux.exe, 00000007.00000002.2334570142.00007FFD93796000.00000002.00000001.01000000.00000009.sdmp | String found in binary or memory: https://streams.videolan.org/upload/ |
Source: K064a7Rfk7.msi, utest.dll.2.dr | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACC6BDC | 5_2_00007FF7AACC6BDC |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACDAFB4 | 5_2_00007FF7AACDAFB4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACB5D28 | 5_2_00007FF7AACB5D28 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACEAEC4 | 5_2_00007FF7AACEAEC4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACC63AC | 5_2_00007FF7AACC63AC |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACCD814 | 5_2_00007FF7AACCD814 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACCC5F4 | 5_2_00007FF7AACCC5F4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACDD6D4 | 5_2_00007FF7AACDD6D4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACE9B88 | 5_2_00007FF7AACE9B88 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACBEB1C | 5_2_00007FF7AACBEB1C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACDCC78 | 5_2_00007FF7AACDCC78 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACC5C50 | 5_2_00007FF7AACC5C50 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACE89F8 | 5_2_00007FF7AACE89F8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AAD029C0 | 5_2_00007FF7AAD029C0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACEE980 | 5_2_00007FF7AACEE980 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACC8930 | 5_2_00007FF7AACC8930 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACB4A28 | 5_2_00007FF7AACB4A28 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACE6A48 | 5_2_00007FF7AACE6A48 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACE8F1C | 5_2_00007FF7AACE8F1C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACE8108 | 5_2_00007FF7AACE8108 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACB4060 | 5_2_00007FF7AACB4060 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACD907C | 5_2_00007FF7AACD907C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACDC044 | 5_2_00007FF7AACDC044 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACCFDF4 | 5_2_00007FF7AACCFDF4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACDBDF0 | 5_2_00007FF7AACDBDF0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACBED54 | 5_2_00007FF7AACBED54 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACD0EA4 | 5_2_00007FF7AACD0EA4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACCEE64 | 5_2_00007FF7AACCEE64 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACD4E34 | 5_2_00007FF7AACD4E34 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACB4E4C | 5_2_00007FF7AACB4E4C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACE0E38 | 5_2_00007FF7AACE0E38 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACF8400 | 5_2_00007FF7AACF8400 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACE936C | 5_2_00007FF7AACE936C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACBF394 | 5_2_00007FF7AACBF394 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACCE350 | 5_2_00007FF7AACCE350 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AAD024F0 | 5_2_00007FF7AAD024F0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACBE504 | 5_2_00007FF7AACBE504 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACD84C4 | 5_2_00007FF7AACD84C4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AAD05418 | 5_2_00007FF7AAD05418 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACB21C4 | 5_2_00007FF7AACB21C4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACEE168 | 5_2_00007FF7AACEE168 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACF8184 | 5_2_00007FF7AACF8184 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACB72F8 | 5_2_00007FF7AACB72F8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACF02FC | 5_2_00007FF7AACF02FC |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACD7250 | 5_2_00007FF7AACD7250 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACE97DC | 5_2_00007FF7AACE97DC |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACDB814 | 5_2_00007FF7AACDB814 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACC1758 | 5_2_00007FF7AACC1758 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACB7730 | 5_2_00007FF7AACB7730 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACFB60C | 5_2_00007FF7AACFB60C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACC9554 | 5_2_00007FF7AACC9554 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACD0684 | 5_2_00007FF7AACD0684 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACFF644 | 5_2_00007FF7AACFF644 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FF71E742EE0 | 7_2_00007FF71E742EE0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FF71E742A10 | 7_2_00007FF71E742A10 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D13A0 | 7_2_00007FFD936D13A0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DB380 | 7_2_00007FFD936DB380 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F33E0 | 7_2_00007FFD936F33E0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936FF2C0 | 7_2_00007FFD936FF2C0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93714330 | 7_2_00007FFD93714330 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93715350 | 7_2_00007FFD93715350 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93716350 | 7_2_00007FFD93716350 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D7260 | 7_2_00007FFD936D7260 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DC2F0 | 7_2_00007FFD936DC2F0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DA1B0 | 7_2_00007FFD936DA1B0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DC1A0 | 7_2_00007FFD936DC1A0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93701160 | 7_2_00007FFD93701160 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DD210 | 7_2_00007FFD936DD210 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD937030A0 | 7_2_00007FFD937030A0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DB150 | 7_2_00007FFD936DB150 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DB790 | 7_2_00007FFD936DB790 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93754840 | 7_2_00007FFD93754840 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F6820 | 7_2_00007FFD936F6820 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DE820 | 7_2_00007FFD936DE820 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F87F0 | 7_2_00007FFD936F87F0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DB6A0 | 7_2_00007FFD936DB6A0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D1730 | 7_2_00007FFD936D1730 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DD700 | 7_2_00007FFD936DD700 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DD5C0 | 7_2_00007FFD936DD5C0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DB5C0 | 7_2_00007FFD936DB5C0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F3580 | 7_2_00007FFD936F3580 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93780640 | 7_2_00007FFD93780640 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93713560 | 7_2_00007FFD93713560 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936FC650 | 7_2_00007FFD936FC650 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F24D0 | 7_2_00007FFD936F24D0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DE4C0 | 7_2_00007FFD936DE4C0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DB460 | 7_2_00007FFD936DB460 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DA520 | 7_2_00007FFD936DA520 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD937144D0 | 7_2_00007FFD937144D0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD9371CBE0 | 7_2_00007FFD9371CBE0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D3B87 | 7_2_00007FFD936D3B87 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93712B60 | 7_2_00007FFD93712B60 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93732B80 | 7_2_00007FFD93732B80 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D1C30 | 7_2_00007FFD936D1C30 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93703C00 | 7_2_00007FFD93703C00 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F2BF0 | 7_2_00007FFD936F2BF0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93715B00 | 7_2_00007FFD93715B00 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DBA70 | 7_2_00007FFD936DBA70 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93702B40 | 7_2_00007FFD93702B40 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD9377DAA0 | 7_2_00007FFD9377DAA0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D99C0 | 7_2_00007FFD936D99C0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD937009B0 | 7_2_00007FFD937009B0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DD9B0 | 7_2_00007FFD936DD9B0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DE9A0 | 7_2_00007FFD936DE9A0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D1990 | 7_2_00007FFD936D1990 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F5980 | 7_2_00007FFD936F5980 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D9A50 | 7_2_00007FFD936D9A50 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DB8D0 | 7_2_00007FFD936DB8D0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DD8D0 | 7_2_00007FFD936DD8D0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD937028B0 | 7_2_00007FFD937028B0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93704920 | 7_2_00007FFD93704920 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DD030 | 7_2_00007FFD936DD030 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DB030 | 7_2_00007FFD936DB030 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D6E70 | 7_2_00007FFD936D6E70 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F2F20 | 7_2_00007FFD936F2F20 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DDEF0 | 7_2_00007FFD936DDEF0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93711E10 | 7_2_00007FFD93711E10 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93702D90 | 7_2_00007FFD93702D90 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DBE20 | 7_2_00007FFD936DBE20 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936EFDF0 | 7_2_00007FFD936EFDF0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F4C80 | 7_2_00007FFD936F4C80 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936D9D50 | 7_2_00007FFD936D9D50 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936F2D20 | 7_2_00007FFD936F2D20 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD93712CC0 | 7_2_00007FFD93712CC0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936DCCE0 | 7_2_00007FFD936DCCE0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA378A430 | 7_2_00007FFDA378A430 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA378A720 | 7_2_00007FFDA378A720 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA378B8D0 | 7_2_00007FFDA378B8D0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA378C6E0 | 7_2_00007FFDA378C6E0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA37890E0 | 7_2_00007FFDA37890E0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3785730 | 7_2_00007FFDA3785730 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3785FA0 | 7_2_00007FFDA3785FA0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA382A828 | 7_2_00007FFDA382A828 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA381E7CC | 7_2_00007FFDA381E7CC |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA378647B | 7_2_00007FFDA378647B |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA382E488 | 7_2_00007FFDA382E488 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA38369FC | 7_2_00007FFDA38369FC |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA382E91C | 7_2_00007FFDA382E91C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA378B000 | 7_2_00007FFDA378B000 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA382EF9C | 7_2_00007FFDA382EF9C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3826DC0 | 7_2_00007FFDA3826DC0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA381ECD8 | 7_2_00007FFDA381ECD8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3827304 | 7_2_00007FFDA3827304 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA382330C | 7_2_00007FFDA382330C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA383B290 | 7_2_00007FFDA383B290 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA378B06A | 7_2_00007FFDA378B06A |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3823714 | 7_2_00007FFDA3823714 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA38336A4 | 7_2_00007FFDA38336A4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3823510 | 7_2_00007FFDA3823510 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3837BFC | 7_2_00007FFDA3837BFC |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA383B92C | 7_2_00007FFDA383B92C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3823D58 | 7_2_00007FFDA3823D58 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3824264 | 7_2_00007FFDA3824264 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA38345D4 | 7_2_00007FFDA38345D4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3820C10 | 7_2_00007FFDA3820C10 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA382CB74 | 7_2_00007FFDA382CB74 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3788B80 | 7_2_00007FFDA3788B80 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA382C8F8 | 7_2_00007FFDA382C8F8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3828E98 | 7_2_00007FFDA3828E98 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3830E00 | 7_2_00007FFDA3830E00 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3788D80 | 7_2_00007FFDA3788D80 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3821200 | 7_2_00007FFDA3821200 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA38397F8 | 7_2_00007FFDA38397F8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDAC0F8DB0 | 7_2_00007FFDAC0F8DB0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDAC0F68B0 | 7_2_00007FFDAC0F68B0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDAC103AA7 | 7_2_00007FFDAC103AA7 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDAC104B4A | 7_2_00007FFDAC104B4A |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C07820 | 11_2_00C07820 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C0C031 | 11_2_00C0C031 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C08174 | 11_2_00C08174 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C032F0 | 11_2_00C032F0 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C193ED | 11_2_00C193ED |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C0D3B0 | 11_2_00C0D3B0 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C145D8 | 11_2_00C145D8 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C05590 | 11_2_00C05590 |
Source: api-ms-win-crt-convert-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-filesystem-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-console-l1-2-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-conio-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-file-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-rtlsupport-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-crt-environment-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-file-l1-2-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-libraryloader-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-sysinfo-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-memory-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-processthreads-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-heap-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-util-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-errorhandling-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-interlocked-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-processenvironment-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-synch-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-file-l2-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-console-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-timezone-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-handle-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-string-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-synch-l1-2-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-profile-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-debug-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-localization-l1-2-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-namedpipe-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-datetime-l1-1-0.dll.2.dr | Static PE information: No import functions for PE file found |
Source: api-ms-win-core-processthreads-l1-1-1.dll.2.dr | Static PE information: No import functions for PE file found |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: windows.ui.immersive.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\msiexec.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: obs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: avcodec-60.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: avutil-58.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: avformat-60.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: w32-pthreads.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: avutil-58.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: swresample-4.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\createdump.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\createdump.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\createdump.exe | Section loaded: dbgcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\createdump.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: | Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb source: createdump.exe, 00000008.00000002.2309946294.00007FF7C76D8000.00000002.00000001.01000000.00000006.sdmp, createdump.exe, 00000008.00000000.2304497963.00007FF7C76D8000.00000002.00000001.01000000.00000006.sdmp |
Source: | Binary string: C:\ReleaseAI\win\Release\bin\x86\embeddeduiproxy.pdb= source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\WinUiBootstrapperEui\WinUiBootstrapperEui.pdb)) source: K064a7Rfk7.msi |
Source: | Binary string: ucrtbase.pdb source: K064a7Rfk7.msi |
Source: | Binary string: api-ms-win-core-file-l1-2-0.pdb source: api-ms-win-core-file-l1-2-0.dll.2.dr |
Source: | Binary string: api-ms-win-core-memory-l1-1-0.pdb source: api-ms-win-core-memory-l1-1-0.dll.2.dr |
Source: | Binary string: api-ms-win-core-debug-l1-1-0.pdb source: api-ms-win-core-debug-l1-1-0.dll.2.dr |
Source: | Binary string: Microsoft.Web.WebView2.Core.pdbGCTL source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\custact\x86\SoftwareDetector.pdbm source: K064a7Rfk7.msi |
Source: | Binary string: E:\BA\201\s\140_release\vcrt_fwd_x86_release\Release\vcamp140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: K064a7Rfk7.msi |
Source: | Binary string: E:\BA\201\s\140_release\vcrt_fwd_x86_release\Release\vccorlib140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdbGCTL source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\WinUiBootstrapperEui\WinUiBootstrapperEui.pdb source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\stubs\x86\ExternalUi.pdb source: K064a7Rfk7.msi |
Source: | Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: api-ms-win-core-processthreads-l1-1-1.dll.2.dr |
Source: | Binary string: api-ms-win-core-heap-l1-1-0.pdb source: api-ms-win-core-heap-l1-1-0.dll.2.dr |
Source: | Binary string: D:\a\_work\1\s\140_release\vcrt_fwd_x86_release\Release\msvcp140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: api-ms-win-core-namedpipe-l1-1-0.dll.2.dr |
Source: | Binary string: D:\releases\dva\shared\adobe\utest\lib\win\release\64\utest.pdb source: utest.dll.2.dr |
Source: | Binary string: E:\BA\201\s\140_release\vcrt_fwd_x86_release\Release\vcomp140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\1\s\Win32\Release\Microsoft.Toolkit.Win32.UI.XamlApplication\Microsoft.Toolkit.Win32.UI.XamlHost.pdb!! source: K064a7Rfk7.msi |
Source: | Binary string: d:\a01\_work\12\s\\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: obs-ffmpeg-mux.exe, 00000007.00000002.2338386873.00007FFDAC131000.00000002.00000001.01000000.0000000C.sdmp, vcruntime140.dll.2.dr |
Source: | Binary string: D:\releases\dva\shared\adobe\utest\lib\win\release\64\utest.pdb((! source: utest.dll.2.dr |
Source: | Binary string: api-ms-win-core-file-l2-1-0.pdb source: api-ms-win-core-file-l2-1-0.dll.2.dr |
Source: | Binary string: C:\a\_work\1\s\BuildOutput\Release\x86\Microsoft.UI.Xaml\Microsoft.UI.Xaml.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\_work\1\s\140_release\vcrt_fwd_x86_release\Release\vcruntime140_app.pdb source: K064a7Rfk7.msi |
Source: | Binary string: obs-ffmpeg-mux.pdb source: obs-ffmpeg-mux.exe, 00000007.00000002.2315346958.00007FF71E745000.00000002.00000001.01000000.00000005.sdmp, obs-ffmpeg-mux.exe, 00000007.00000000.2304470611.00007FF71E745000.00000002.00000001.01000000.00000005.sdmp |
Source: | Binary string: D:\a\1\s\Win32\Release\Microsoft.Toolkit.Win32.UI.XamlApplication\Microsoft.Toolkit.Win32.UI.XamlHost.pdb source: K064a7Rfk7.msi |
Source: | Binary string: C:\ReleaseAI\win\Release\bin\x86\embeddeduiproxy.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\debug\createdump\createdump.pdb;;;GCTL source: createdump.exe, 00000008.00000002.2309946294.00007FF7C76D8000.00000002.00000001.01000000.00000006.sdmp, createdump.exe, 00000008.00000000.2304497963.00007FF7C76D8000.00000002.00000001.01000000.00000006.sdmp |
Source: | Binary string: D:\a\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: K064a7Rfk7.msi |
Source: | Binary string: D:\Projects\WinRAR\rar\build\unrar64\Release\UnRAR.pdb source: UnRar.exe, 00000005.00000002.2303651093.00007FF7AAD08000.00000002.00000001.01000000.00000004.sdmp, UnRar.exe, 00000005.00000000.2292652385.00007FF7AAD08000.00000002.00000001.01000000.00000004.sdmp |
Source: | Binary string: C:\ReleaseAI\win\Release\custact\x86\SoftwareDetector.pdb source: K064a7Rfk7.msi |
Source: | Binary string: Microsoft.Web.WebView2.Core.pdb source: K064a7Rfk7.msi |
Source: | Binary string: ucrtbase.pdbUGP source: K064a7Rfk7.msi |
Source: | Binary string: api-ms-win-core-profile-l1-1-0.pdb source: api-ms-win-core-profile-l1-1-0.dll.2.dr |
Source: | Binary string: w32-pthreads.pdb source: obs-ffmpeg-mux.exe, 00000007.00000002.2338942242.00007FFDAC148000.00000002.00000001.01000000.0000000B.sdmp |
Source: | Binary string: C:\ReleaseAI\win\Release\custact\x86\AICustAct.pdb source: K064a7Rfk7.msi, MSIE1FA.tmp.2.dr, MSIE336.tmp.2.dr |
Source: | Binary string: D:\a\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdbGCTL source: K064a7Rfk7.msi |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE0DE.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\BCUninstaller.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE18B.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE1FA.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\utest.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\zlib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\createdump.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\swscale-7.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\avutil-58.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\vcruntime140.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\msvcp140.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE336.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\swresample-4.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE249.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE1CA.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Windows\Installer\MSIE289.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\avformat-60.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-console-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\vcruntime140_1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\w32-pthreads.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\avcodec-60.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFD936EB840 FreeLibrary,free,calloc,MultiByteToWideChar,MultiByteToWideChar,MultiByteToWideChar,GetModuleHandleW,GetProcAddress,GetProcAddress,LoadLibraryExW,_aligned_free,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,_errno,GetModuleHandleW,GetProcAddress,GetProcAddress,LoadLibraryExA,FreeLibrary,free,wcslen,GetModuleFileNameW,_aligned_free,_aligned_free,_aligned_free,wcscpy,LoadLibraryExW,LoadLibraryExW,_aligned_free,_aligned_free,_aligned_free,_aligned_free,_aligned_free,_aligned_free,_aligned_free,GetSystemDirectoryW,GetSystemDirectoryW,GetSystemDirectoryW,wcscpy,LoadLibraryExW,_aligned_free,_aligned_free,_aligned_free,_aligned_free, | 7_2_00007FFD936EB840 |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-file-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE0DE.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-debug-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-handle-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-console-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\msvcp140.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-datetime-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE336.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-heap-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\BCUninstaller.exe | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-synch-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-processthreads-l1-1-1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-rtlsupport-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE249.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE18B.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-timezone-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-errorhandling-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-crt-filesystem-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE1CA.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-namedpipe-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-interlocked-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE1FA.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-processenvironment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\zlib.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\utest.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-crt-convert-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-libraryloader-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-file-l2-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-crt-conio-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-localization-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Windows\Installer\MSIE289.tmp | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-util-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-processthreads-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-synch-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-console-l1-2-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-sysinfo-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-crt-environment-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\vcruntime140_1.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-string-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-memory-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-profile-l1-1-0.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\swscale-7.dll | Jump to dropped file |
Source: C:\Windows\System32\msiexec.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\api-ms-win-core-file-l1-1-0.dll | Jump to dropped file |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACCCED8 FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn, | 5_2_00007FF7AACCCED8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACFF850 FindFirstFileExA, | 5_2_00007FF7AACFF850 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA378A430 TryEnterCriticalSection,TerminateThread,SetThreadpoolStackInformation,SetConsoleHistoryInfo,PrefetchVirtualMemory,GetQueuedCompletionStatusEx,SystemTimeToFileTime,GetExitCodeProcess,CreateSymbolicLinkTransactedW,FindFirstFileW,LoadModule,OpenFile,OpenThread,SetFileTime,WaitForThreadpoolWorkCallbacks,FreeLibraryAndExitThread,PowerCreateRequest,InterlockedPushListSListEx,LocalFileTimeToFileTime,FindCloseChangeNotification,CreateThreadpoolCleanupGroup,QueryFullProcessImageNameW,Wow64GetThreadSelectorEntry,IsValidNLSVersion,FreeLibraryAndExitThread,CreateEventExW,SetPriorityClass,IsValidNLSVersion,RegisterApplicationRecoveryCallback,GetFileSize,GlobalFree,GetFileMUIInfo,SetConsoleActiveScreenBuffer,LCIDToLocaleName, | 7_2_00007FFDA378A430 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3785730 SetFocus,CreateFileTransactedW,GetWindowContextHelpId,VirtualAlloc,FindNextVolumeMountPointW,OpenWaitableTimerW,FindNextStreamW,AddSIDToBoundaryDescriptor,EnterCriticalSection,DeleteSynchronizationBarrier,RemoveDirectoryTransactedW,LogicalToPhysicalPoint,OpenClipboard,SetWindowRgn,GetCommProperties,ShowCursor,GetFileBandwidthReservation,VirtualAlloc,GetProcessHeap,DeleteTimerQueueTimer,WriteTapemark,GlobalHandle,SetStdHandle,CreateTimerQueueTimer,GetProcessVersion,ReadConsoleOutputW,FindFirstFileW,GetProcessVersion,GetConsoleTitleW,HeapAlloc, | 7_2_00007FFDA3785730 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA37872D0 RegisterClassW,CreateWindowExW,ShowWindow,UpdateWindow,FindFirstFileW,FindClose,GetTempPathW,GetFileAttributesW,GetDC,CreateCompatibleBitmap,CreateCompatibleDC,SelectObject,CreateSolidBrush,FillRect,DeleteObject,GetObjectW,GetDIBits,SelectObject,DeleteDC,DeleteObject,CreateDirectoryW,type_info::_name_internal_method,GetMessageW,TranslateMessage,DispatchMessageW, | 7_2_00007FFDA37872D0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA38345D4 FindFirstFileExW, | 7_2_00007FFDA38345D4 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C12159 FindFirstFileExW, | 11_2_00C12159 |
Source: obs-ffmpeg-mux.exe, 00000007.00000002.2315188964.000001D153220000.00000004.00001000.00020000.00000000.sdmp, obs-ffmpeg-mux.exe, 00000007.00000002.2315129206.000001D153170000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000B.00000002.2323731959.0000000000C00000.00000040.00000400.00020000.00000000.sdmp | Binary or memory string: |PIPE|vbOXtRAYipc d |
Source: explorer.exe, 0000000B.00000002.2323731959.0000000000C00000.00000040.00000400.00020000.00000000.sdmp | Binary or memory string: |vbOXgUEST || |
Source: classes.jsa.2.dr | Binary or memory string: [Ljava/lang/VirtualMachineError; |
Source: classes.jsa.2.dr | Binary or memory string: ,jdk.vm.ci.hotspot.HotSpotJVMCIBackendFactory |
Source: obs-ffmpeg-mux.exe, 00000007.00000002.2326785273.00007FFD9209A000.00000002.00000001.01000000.00000008.sdmp | Binary or memory string: vmncVMware Screen Codec / VMware Video @! |
Source: classes.jsa.2.dr | Binary or memory string: ()Ljdk/vm/ci/runtime/JVMCICompiler; |
Source: classes.jsa.2.dr | Binary or memory string: VirtualMachineError.java |
Source: K064a7Rfk7.msi | Binary or memory string: HKEY_USERSRegOpenKeyTransactedW::NetUserGetInfo() failed with error: \@invalid string_view positionVMware, Inc.VMware Virtual PlatformVMware7,1VMware20,1innotek GmbHVirtualBoxMicrosoft CorporationVirtual MachineVRTUALACRSYSA M IGetting system informationManufacturer [Model [BIOS [\\?\UNC\\\?\shim_clone%d.%d.%d.%dDllGetVersion[%!]%!ProgramFilesFolderCommonFilesFolderDesktopFolderAllUsersDesktopFolderAppDataFolderFavoritesFolderStartMenuFolderProgramMenuFolderStartupFolderFontsFolderLocalAppDataFolderCommonAppDataFolderProgramFiles64FolderProgramFilesProgramW6432SystemFolderSystem32FolderWindowsFolderWindowsVolumeTempFolderSETUPEXEDIRshfolder.dllSHGetFolderPathWProgramFilesAPPDATAPROGRAMFILES&+ |
Source: explorer.exe, 0000000B.00000002.2323519946.0000000000788000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000002.2323519946.0000000000747000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: classes.jsa.2.dr | Binary or memory string: jdk/vm/ci/common/JVMCIError |
Source: classes.jsa.2.dr | Binary or memory string: jdk.vm.ci.services.JVMCIServiceLocator |
Source: classes.jsa.2.dr | Binary or memory string: jdk.vm.ci.hotspot.aarch64.AArch64HotSpotJVMCIBackendFactory |
Source: avcodec-60.dll.2.dr | Binary or memory string: vmncVMware Screen Codec / VMware Video @ |
Source: classes.jsa.2.dr | Binary or memory string: &jdk.vm.ci.services.JVMCIServiceLocator |
Source: classes.jsa.2.dr | Binary or memory string: ()Ljdk/vm/ci/runtime/JVMCIRuntime; |
Source: obs-ffmpeg-mux.exe, 00000007.00000002.2315188964.000001D153220000.00000004.00001000.00020000.00000000.sdmp, obs-ffmpeg-mux.exe, 00000007.00000002.2315129206.000001D153170000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000B.00000002.2323731959.0000000000C00000.00000040.00000400.00020000.00000000.sdmp | Binary or memory string: |vbOXmINIrDRdn || |
Source: classes.jsa.2.dr | Binary or memory string: java/lang/VirtualMachineError.class |
Source: classes.jsa.2.dr | Binary or memory string: 7jdk.vm.ci.hotspot.amd64.AMD64HotSpotJVMCIBackendFactory |
Source: obs-ffmpeg-mux.exe, 00000007.00000002.2315188964.000001D153220000.00000004.00001000.00020000.00000000.sdmp, obs-ffmpeg-mux.exe, 00000007.00000002.2315129206.000001D153170000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000B.00000002.2323731959.0000000000C00000.00000040.00000400.00020000.00000000.sdmp | Binary or memory string: |vbOXtRAYipc || |
Source: classes.jsa.2.dr | Binary or memory string: <"()Ljdk/vm/ci/runtime/JVMCIRuntime; |
Source: classes.jsa.2.dr | Binary or memory string: [Ljava/lang/VirtualMachineError; |
Source: classes.jsa.2.dr | Binary or memory string: java/lang/VirtualMachineError |
Source: classes.jsa.2.dr | Binary or memory string: org.graalvm.compiler.hotspot.HotSpotGraalJVMCIServiceLocator |
Source: classes.jsa.2.dr | Binary or memory string: %jdk/vm/ci/hotspot/HotSpotJVMCIRuntime |
Source: UnRar.exe, 00000005.00000003.2301496595.000001966AD82000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: 7KqemUeu |
Source: classes.jsa.2.dr | Binary or memory string: jdk/vm/ci/hotspot/HotSpotJVMCIRuntime |
Source: classes.jsa.2.dr | Binary or memory string: ;jdk.vm.ci.hotspot.aarch64.AArch64HotSpotJVMCIBackendFactory |
Source: classes.jsa.2.dr | Binary or memory string: jdk/vm/ci/runtime/JVMCI |
Source: classes.jsa.2.dr | Binary or memory string: )()Ljdk/vm/ci/hotspot/HotSpotJVMCIRuntime; |
Source: classes.jsa.2.dr | Binary or memory string: UG#java/lang/VirtualMachineError.class |
Source: classes.jsa.2.dr | Binary or memory string: #()Ljdk/vm/ci/runtime/JVMCICompiler; |
Source: classes.jsa.2.dr | Binary or memory string: jdk.vm.ci.hotspot.HotSpotJVMCIBackendFactory |
Source: classes.jsa.2.dr | Binary or memory string: jdk.vm.ci.hotspot.amd64.AMD64HotSpotJVMCIBackendFactory |
Source: classes.jsa.2.dr | Binary or memory string: <org.graalvm.compiler.hotspot.HotSpotGraalJVMCIServiceLocator |
Source: classes.jsa.2.dr | Binary or memory string: Ljava/lang/VirtualMachineError; |
Source: avcodec-60.dll.2.dr | Binary or memory string: VMware Screen Codec / VMware Video |
Source: classes.jsa.2.dr | Binary or memory string: ()Ljdk/vm/ci/hotspot/HotSpotJVMCIRuntime; |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACF1F20 SetUnhandledExceptionFilter, | 5_2_00007FF7AACF1F20 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACF110C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 5_2_00007FF7AACF110C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACF1D78 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 5_2_00007FF7AACF1D78 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\UnRar.exe | Code function: 5_2_00007FF7AACF61D8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 5_2_00007FF7AACF61D8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FF71E743E04 SetUnhandledExceptionFilter, | 7_2_00007FF71E743E04 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FF71E743C5C IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 7_2_00007FF71E743C5C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FF71E743774 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 7_2_00007FF71E743774 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA38267D0 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 7_2_00007FFDA38267D0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3818848 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 7_2_00007FFDA3818848 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: 7_2_00007FFDA3818594 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 7_2_00007FFDA3818594 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\createdump.exe | Code function: 8_2_00007FF7C76D3074 SetUnhandledExceptionFilter, | 8_2_00007FF7C76D3074 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\createdump.exe | Code function: 8_2_00007FF7C76D2ECC IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 8_2_00007FF7C76D2ECC |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\createdump.exe | Code function: 8_2_00007FF7C76D2984 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 8_2_00007FF7C76D2984 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C08864 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 11_2_00C08864 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C0C95A IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 11_2_00C0C95A |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C084B1 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 11_2_00C084B1 |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 11_2_00C08641 SetUnhandledExceptionFilter, | 11_2_00C08641 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: SetThreadErrorMode,SetEventWhenCallbackReturns,AddDllDirectory,FindVolumeClose,GetOEMCP,ClearCommError,WriteProfileStringW,CreatePrivateNamespaceW,DeleteAtom,GetNumaNodeProcessorMask,GetCommConfig,SearchPathW,SetFileCompletionNotificationModes,BackupRead,GetTimeZoneInformation,GetMetaFileW,GetPrivateProfileSectionW,GetMaximumProcessorCount,SignalObjectAndWait,GetThreadIdealProcessorEx,DeleteTimerQueueEx,GetTextExtentPointI,LockResource,FindNextVolumeW,GlobalReAlloc,GlobalAlloc,ExtSelectClipRgn,GetEnhMetaFilePaletteEntries,DeleteTimerQueue,ChangeTimerQueueTimer,VerifyScripts,ClosePrivateNamespace,GetSystemPowerStatus,GetModuleHandleW,IsBadStringPtrW,GetNearestPaletteIndex,SetSearchPathMode,ReadConsoleOutputCharacterW,SetCalendarInfoW,LocaleNameToLCID,InitializeConditionVariable,GetWinMetaFileBits,GetLocaleInfoW,FindNextVolumeMountPointW,EnumTimeFormatsEx,SetFileTime,GetTimeFormatW,GetCharABCWidthsFloatW,LeaveCriticalSectionWhenCallbackReturns,WaitForThreadpoolWorkCallbacks, | 7_2_00007FFDA378C6E0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: FreeDDElParam,OpenSemaphoreW,GetThreadGroupAffinity,GetVolumeNameForVolumeMountPointW,FrameRect,WaitForMultipleObjectsEx,GetSystemTimes,WideCharToMultiByte,VirtualProtect,GetTempPathW,GetNamedPipeClientSessionId,SystemTimeToTzSpecificLocalTimeEx,GetProcessHandleCount,SetThreadStackGuarantee,LocalFlags,GetFileMUIInfo,SystemTimeToFileTime,LocalHandle,SetProcessPriorityBoost,EnumResourceTypesExW,TzSpecificLocalTimeToSystemTimeEx,GetLocaleInfoW,SetConsoleActiveScreenBuffer,WaitForDebugEvent,GetConsoleTitleW,GetThreadTimes,GetNamedPipeHandleStateW,InitializeConditionVariable,SetConsoleActiveScreenBuffer,VirtualProtect,GlobalFree,GetConsoleTitleW,VerSetConditionMask,GetCPInfo,FreeLibrary,SetCurrentConsoleFontEx,SetThreadDescription,GetUserDefaultLCID,SetLocalTime,HeapQueryInformation,FlsAlloc,GetLastError,GetThreadErrorMode,WaitForThreadpoolWaitCallbacks,GetDiskFreeSpaceExW,GlobalMemoryStatus,WriteProfileSectionW,AddIntegrityLabelToBoundaryDescriptor,CancelSynchronousIo,GetDriveTypeW, | 7_2_00007FFDA37890E0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: EnumSystemLocalesW, | 7_2_00007FFDA382F94C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: GetLocaleInfoW, | 7_2_00007FFDA382FDCC |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW, | 7_2_00007FFDA383818C |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, | 7_2_00007FFDA3838650 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: EnumSystemLocalesW, | 7_2_00007FFDA38385B8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: EnumSystemLocalesW, | 7_2_00007FFDA38384E8 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 7_2_00007FFDA3838BD4 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: GetLocaleInfoW, | 7_2_00007FFDA3838AA0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 7_2_00007FFDA38389F0 |
Source: C:\Users\user\AppData\Roaming\Barsoc Quite Sols\Joas App\obs-ffmpeg-mux.exe | Code function: GetLocaleInfoW, | 7_2_00007FFDA3838898 |