Source: unknown | Process created: C:\Users\user\Desktop\view.exe 'C:\Users\user\Desktop\view.exe' |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p |
Source: C:\Users\user\Desktop\view.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\Public\StartPublic.cmd' ' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\choice.exe choice /n /c yn /t 1 /d y |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\ProgramData\screen.exe 'C:\ProgramData\screen.exe' elevate 'C:\ProgramData\screen.exe' exec hide 'C:\Users\Public\Public.cmd' |
Source: C:\ProgramData\screen.exe | Process created: C:\ProgramData\screen.exe 'C:\ProgramData\screen.exe' exec hide 'C:\Users\Public\Public.cmd' |
Source: C:\ProgramData\screen.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\Public\Public.cmd' ' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsSense.exe' /v Defender1 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseCncProxy.exe' /v Defender2 /t REG_SZ /d 'cmd.exe' /f |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseIR.exe' /v Defender3 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseNdr.exe' /v Defender4 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseSampleUploader.exe' /v Defender5 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseCE.exe' /v Defender6 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ConfigSecurityPolicy.exe' /v Defender7 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe' /v Defender8 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe' /v Defender9 /t REG_SZ /d 'cmd.exe' /f |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NisSrv.exe' /v Defender10 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OfflineScannerShell.exe' /v Defender11 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender1 /t REG_SZ /d 'MsSense.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender2 /t REG_SZ /d 'SenseCncProxy.exe' /f |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender3 /t REG_SZ /d 'SenseIR.exe' /f |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k unistacksvcgroup |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender4 /t REG_SZ /d 'SenseNdr.exe' /f |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender5 /t REG_SZ /d 'SenseSampleUploader.exe' /f |
Source: unknown | Process created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender6 /t REG_SZ /d 'SenseCE.exe' /f |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender7 /t REG_SZ /d 'ConfigSecurityPolicy.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender8 /t REG_SZ /d 'MpCmdRun.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender9 /t REG_SZ /d 'MsMpEng.exe' /f |
Source: C:\Users\user\Desktop\view.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\Public\StartPublic.cmd' ' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\choice.exe choice /n /c yn /t 1 /d y |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\ProgramData\screen.exe 'C:\ProgramData\screen.exe' elevate 'C:\ProgramData\screen.exe' exec hide 'C:\Users\Public\Public.cmd' |
Source: C:\ProgramData\screen.exe | Process created: C:\ProgramData\screen.exe 'C:\ProgramData\screen.exe' exec hide 'C:\Users\Public\Public.cmd' |
Source: C:\ProgramData\screen.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\Public\Public.cmd' ' |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsSense.exe' /v Defender1 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseCncProxy.exe' /v Defender2 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseIR.exe' /v Defender3 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseNdr.exe' /v Defender4 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseSampleUploader.exe' /v Defender5 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseCE.exe' /v Defender6 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ConfigSecurityPolicy.exe' /v Defender7 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe' /v Defender8 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe' /v Defender9 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NisSrv.exe' /v Defender10 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OfflineScannerShell.exe' /v Defender11 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender1 /t REG_SZ /d 'MsSense.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender2 /t REG_SZ /d 'SenseCncProxy.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender3 /t REG_SZ /d 'SenseIR.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender4 /t REG_SZ /d 'SenseNdr.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender5 /t REG_SZ /d 'SenseSampleUploader.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender6 /t REG_SZ /d 'SenseCE.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender7 /t REG_SZ /d 'ConfigSecurityPolicy.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender8 /t REG_SZ /d 'MpCmdRun.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender9 /t REG_SZ /d 'MsMpEng.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender5 /t REG_SZ /d 'SenseSampleUploader.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender5 /t REG_SZ /d 'SenseSampleUploader.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender3 /t REG_SZ /d 'SenseIR.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender9 /t REG_SZ /d 'MsMpEng.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SenseCncProxy.exe' /v Defender2 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsSense.exe' /v Defender1 /t REG_SZ /d 'cmd.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender5 /t REG_SZ /d 'SenseSampleUploader.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender3 /t REG_SZ /d 'SenseIR.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender7 /t REG_SZ /d 'ConfigSecurityPolicy.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe reg.exe ADD 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun' /v Defender9 /t REG_SZ /d 'MsMpEng.exe' /f |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: unknown unknown |