Source: AIuBPU1Zm5.exe, type: SAMPLE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: AIuBPU1Zm5.exe, type: SAMPLE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: AIuBPU1Zm5.exe, type: SAMPLE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 1.0.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 1.0.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 1.0.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 2.2.tasksche.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 2.2.tasksche.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 2.2.tasksche.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 1.2.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 1.2.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 1.2.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 0.0.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 0.0.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 0.0.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 0.2.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 0.2.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 0.2.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 2.0.tasksche.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 2.0.tasksche.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 2.0.tasksche.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 1.2.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 1.2.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 1.2.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 0.0.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 0.0.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 0.0.AIuBPU1Zm5.exe.7100a4.1.raw.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 0.2.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 0.2.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 0.2.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 1.0.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 1.0.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 1.0.AIuBPU1Zm5.exe.7100a4.1.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 0.2.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 0.2.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 0.2.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 0.0.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 0.0.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 0.0.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 1.0.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 1.0.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 1.0.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 1.2.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: 1.2.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 1.2.AIuBPU1Zm5.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: 00000002.00000002.318934664.000000000040E000.00000008.00000001.01000000.00000005.sdmp, type: MEMORY | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 00000002.00000000.315196183.000000000040E000.00000008.00000001.01000000.00000005.sdmp, type: MEMORY | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 00000001.00000000.312995760.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 00000000.00000000.311773719.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 00000001.00000002.315255469.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: 00000000.00000002.319681022.0000000000710000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: C:\Windows\tasksche.exe, type: DROPPED | Matched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (Nextron Systems) (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T |
Source: C:\Windows\tasksche.exe, type: DROPPED | Matched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set |
Source: C:\Windows\tasksche.exe, type: DROPPED | Matched rule: Win32_Ransomware_WannaCry tc_detection_name = WannaCry, tc_detection_factor = , author = ReversingLabs, tc_detection_type = Ransomware |
Source: tasksche.exe.0.dr | Binary string: C\Device\HarddiskVolume2\Windows\SoftwareDistribution\DataStore\Logs |
Source: tasksche.exe.0.dr | Binary string: @\Device\HarddiskVolume2\Windows\System32\ru-RU\WinSATAPI.dll.mui |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\dmvsc.sysT |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\parvdm.sysAUH |
Source: tasksche.exe.0.dr | Binary string: 2\Device\HarddiskVolume2\Windows\System32\fveui.dll |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\wercplsupport.dll |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\QAGENTRT.DLL |
Source: tasksche.exe.0.dr | Binary string: I\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\Locationp |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\crcdisk.sysp |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\dmvsc.sysd |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\NV_AGP.SYS |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\acpipmi.sysH |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\ndiscap.sys |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\cabinet.dll |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5ABCO |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\VMBusHID.sys& |
Source: tasksche.exe.0.dr | Binary string: h\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\System32\mapi32.dll |
Source: tasksche.exe.0.dr | Binary string: +\Device\HarddiskVolume2\Windows\System32\ru_PTC |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\BrSerId.sys |
Source: tasksche.exe.0.dr | Binary string: 2\Device\HarddiskVolume2\Windows\Logs\SystemRestore |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\crcdisk.sys? |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\dmvsc.sys; |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\mskssrv.sys |
Source: tasksche.exe.0.dr | Binary string: D\Device\HarddiskVolume2\Windows\System32\drivers\en-US\ipnat.sys.muip |
Source: tasksche.exe.0.dr | Binary string: `\Device\HarddiskVolume2\Program Files\Windows Media Player\Network Sharing\ConnectionManager.xmlp |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\storvsc.sys, |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RasRip-Package~31bf3856ad364e35~x86~~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SystemRestore-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\desktop.inip |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnky009.catp |
Source: tasksche.exe.0.dr | Binary string: J\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\netrass.inf_loc0D |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\amdk8.sys |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-MiscRedirection-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: 2\Device\HarddiskVolume2\Windows\System32\msdmo.dllF75p |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\dmvsc.sys@ |
Source: tasksche.exe.0.dr | Binary string: 2\Device\HarddiskVolume2\Windows\System32\umrdp.dllSTRP |
Source: tasksche.exe.0.dr | Binary string: 8\Device\HarddiskVolume2\Program Files\AVG\Av\avgcmgr.exeST |
Source: tasksche.exe.0.dr | Binary string: -\Device\HarddiskVolume2\Windows\inf\mshdc.PNFp |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnep004.catp |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnep005.cat |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\1394ohci.sysp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SimpleTCP-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\System32\DFDWiz.exeU0IS$ |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnep004.cat\ |
Source: tasksche.exe.0.dr | Binary string: /\Device\HarddiskVolume2\Windows\inf\ndiscap.PNF |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IE-Troubleshooters-Package~31bf3856ad364e35~x86~~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\intelide.sys |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\TsUsbGD.sys |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\ProgramData\Avg\log\AV16\shredlog.cfgp |
Source: tasksche.exe.0.dr | Binary string: F\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\partmgr.sys.mui |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F94FD5F2AAEFDB64257601230509A4E9H |
Source: tasksche.exe.0.dr | Binary string: Y\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnrc007.catp |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\httpapi.dllpp |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\ListSvc.dll |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\hidbth.sysH |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\arcsas.sysX |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\netpacer.inf_locDa |
Source: tasksche.exe.0.dr | Binary string: U\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0\Icon Files\2c07d841-785f-469b-81db-3ff900796688.png\ |
Source: tasksche.exe.0.dr | Binary string: X\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft |
Source: tasksche.exe.0.dr | Binary string: Z\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb |
Source: tasksche.exe.0.dr | Binary string: x\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0\SCPD |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMI-SNMP-Provider-Package~31bf3856ad364e35~x86~~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: F\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\AppIDp |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\drmkaud.sysCP |
Source: tasksche.exe.0.dr | Binary string: #\Device\HarddiskVolume3\ |
Source: tasksche.exe.0.dr | Binary string: +\Device\HarddiskVolume2\Windows\Performance |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\drmkaud.sys |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\ehome\ehprivjob.exe |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMI-SNMP-Provider-Package~31bf3856ad364e35~x86~~6.1.7601.17514.catW |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\ProgramData\Avg\log\AV16\csllog.cfgLL |
Source: tasksche.exe.0.dr | Binary string: 0\Device\HarddiskVolume2\Windows\inf\keyboard.PNF |
Source: tasksche.exe.0.dr | Binary string: m\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\Myp |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\wbem\WmiApSrv.exe |
Source: tasksche.exe.0.dr | Binary string: o\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\windows-legacy-whql.cat |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnlx004.catp |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\wbem\WmiApSrv.exes\S |
Source: tasksche.exe.0.dr | Binary string: `\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem4.CATWp |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnhp004.catWp |
Source: tasksche.exe.0.dr | Binary string: L\Device\HarddiskVolume2\ProgramData\Microsoft\Windows\Start Menu\desktop.inip |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: O\Device\HarddiskVolume2\Windows\Temp\avg_a04392\avg-secure-search-installer.exep |
Source: tasksche.exe.0.dr | Binary string: -\Device\HarddiskVolume2\Windows\inf\input.PNFp |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\sisraid2.sys |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\parvdm.sysH |
Source: tasksche.exe.0.dr | Binary string: >\Device\HarddiskVolume2\Program Files\AVG Web TuneUp\TBAPI.dllM |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\hdaudbus.inf_loc |
Source: tasksche.exe.0.dr | Binary string: P\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: J\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\battery.inf_loc |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\netsstpt.inf_locBFFRp |
Source: tasksche.exe.0.dr | Binary string: +\Device\HarddiskVolume2\Windows\System32\ru1 |
Source: tasksche.exe.0.dr | Binary string: c\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: {\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\parvdm.sys1 |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\ProgramData\Microsoft\RAC\StateData |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Media-Foundation-Package~31bf3856ad364e35~x86~~6.1.7601.17514.catore.p |
Source: tasksche.exe.0.dr | Binary string: E\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\UAGP35.SYS.mui |
Source: tasksche.exe.0.dr | Binary string: +\Device\HarddiskVolume2\Windows\System32\en_CPU |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: H\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\input.inf_locH |
Source: tasksche.exe.0.dr | Binary string: O\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe |
Source: tasksche.exe.0.dr | Binary string: +\Device\HarddiskVolume2\ProgramData\Avg\log |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\rdpwd.sys |
Source: tasksche.exe.0.dr | Binary string: J\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\ndiscap.inf_loctform. |
Source: tasksche.exe.0.dr | Binary string: \\Device\HarddiskVolume2\ProgramData\Microsoft\Windows\Start Menu\Programs\Remote Access Hoste` |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\ipnat.sys |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0\Icon Files\2c07d841-785f-469b-81db-3ff900796688.png |
Source: tasksche.exe.0.dr | Binary string: 9\Device\HarddiskVolume2\Windows\System32\drivers\mpio.sys |
Source: tasksche.exe.0.dr | Binary string: ~\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0\Icon Files'* |
Source: tasksche.exe.0.dr | Binary string: F\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\cpu.inf_locCC |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\msdsm.sys |
Source: tasksche.exe.0.dr | Binary string: c\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex, |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\ndiscap.sysS, |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Hyper-V-Guest-Integration-Drivers-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnca00d.catp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OpticalMediaDisc-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: ^\Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows |
Source: tasksche.exe.0.dr | Binary string: v\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: 6\Device\HarddiskVolume2\Windows\System32\WinSATAPI.dllp |
Source: tasksche.exe.0.dr | Binary string: r\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\desktop.ini: |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Printing-LocalPrinting-Home-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\ProgramData\Avg\log\AV16\nslog.cfgS |
Source: tasksche.exe.0.dr | Binary string: I\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\lltdio.inf_loc |
Source: tasksche.exe.0.dr | Binary string: G\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\acpi.inf_loc |
Source: tasksche.exe.0.dr | Binary string: ,\Device\HarddiskVolume2\Windows\Temp\_avast_p |
Source: tasksche.exe.0.dr | Binary string: 0\Device\HarddiskVolume2\Windows\inf\netsstpt.PNFwnp |
Source: tasksche.exe.0.dr | Binary string: I\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows Defender |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\msdsm.sys9 |
Source: tasksche.exe.0.dr | Binary string: 7\Device\HarddiskVolume2\Windows\System32\sdiagnhost.exe |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\WUDFRd.sys |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Backup-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: S\Device\HarddiskVolume2\Windows\System32\config\systemprofile\Favorites\desktop.ini |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnbr009.cat1p |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\ProgramData\Avg\log\AV16\publog.cfgk |
Source: tasksche.exe.0.dr | Binary string: V\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chkH |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\udhisapi.dll |
Source: tasksche.exe.0.dr | Binary string: 2\Device\HarddiskVolume2\Windows\ehome\mcupdate.exe |
Source: tasksche.exe.0.dr | Binary string: F\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\HdAudio.sys.muip |
Source: tasksche.exe.0.dr | Binary string: H\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\cdrom.inf_loc |
Source: tasksche.exe.0.dr | Binary string: 8\Device\HarddiskVolume2\Windows\System32\drivers\smb.sysH |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\ProgramData\Avg\log\AV16\schedlog.cfgp |
Source: tasksche.exe.0.dr | Binary string: 7\Device\HarddiskVolume2\Windows\System32\MSMPEG2ENC.DLLp |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\adpahci.sysp |
Source: tasksche.exe.0.dr | Binary string: 7\Device\HarddiskVolume2\Program Files\AVG\Av\avg_us.lngp |
Source: tasksche.exe.0.dr | Binary string: /\Device\HarddiskVolume2\Windows\inf\ndisuio.PNFT` |
Source: tasksche.exe.0.dr | Binary string: j\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\log\av16\avgidpagent.log.1 |
Source: tasksche.exe.0.dr | Binary string: q\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Contentp |
Source: tasksche.exe.0.dr | Binary string: m\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnep003.cat |
Source: tasksche.exe.0.dr | Binary string: x\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001H |
Source: tasksche.exe.0.dr | Binary string: 7\Device\HarddiskVolume2\Program Files\AVG\Av\avg_ru.lng>" |
Source: tasksche.exe.0.dr | Binary string: .\Device\HarddiskVolume2\Windows\inf\wfplwf.PNF |
Source: tasksche.exe.0.dr | Binary string: 2\Device\HarddiskVolume2\Windows\Performance\WinSAT |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WinOcr-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\nfrd960.sys |
Source: tasksche.exe.0.dr | Binary string: H\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\cdrom.inf_locp |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\bthmodem.sys |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\fdPHost.dll |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Program Files\AVG\UiDll\2623 |
Source: tasksche.exe.0.dr | Binary string: z\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.236.gthr |
Source: tasksche.exe.0.dr | Binary string: x\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.002H |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\ws2ifsl.sys |
Source: tasksche.exe.0.dr | Binary string: k\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnlx00w.cat |
Source: tasksche.exe.0.dr | Binary string: p\Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\UPnP Device Host\upnphost8P |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\megasas.sysPD |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\blbdrive.inf_loc |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\blbdrive.inf_locH |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnrc00c.cat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\vsmraid.sysp |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\rasmans.dll |
Source: tasksche.exe.0.dr | Binary string: r\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs1 |
Source: tasksche.exe.0.dr | Binary string: X\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\Windows Error ReportingPU |
Source: tasksche.exe.0.dr | Binary string: /\Device\HarddiskVolume2\Windows\Temp\avg_a04392p |
Source: tasksche.exe.0.dr | Binary string: c\Device\HarddiskVolume2\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibilityum |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NFS-ClientSKU-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnep00b.cat |
Source: tasksche.exe.0.dr | Binary string: 2\Device\HarddiskVolume2\Windows\System32\msdtc.exe}SDTL |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\mrxdav.sys |
Source: tasksche.exe.0.dr | Binary string: a\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntexe.catp |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\aelupsvc.dll |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnlx00d.cat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.ciT |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-RasCMAK-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_KB2534111~31bf3856ad364e35~x86~~6.1.1.0.cat |
Source: tasksche.exe.0.dr | Binary string: L\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\tssecsrv.sys |
Source: tasksche.exe.0.dr | Binary string: A\Device\HarddiskVolume2\Windows\System32\Speech\SpeechUX\sapi.cpl |
Source: tasksche.exe.0.dr | Binary string: L\Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\AppData\Roaming\/ |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\vms3cap.sysST |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\wacompen.sysp |
Source: tasksche.exe.0.dr | Binary string: f\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History68E: |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\tdtcp.sys |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\msdtckrm.dll |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\amdsata.sys |
Source: tasksche.exe.0.dr | Binary string: x\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000H |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Users\Public\Documents\desktop.ini |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-IIS-WebServer-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\HpSAMD.sys F |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\bxvbdx.sys |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WinOcr-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnts003.cat |
Source: tasksche.exe.0.dr | Binary string: r\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLsp |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\auditcse.dll |
Source: tasksche.exe.0.dr | Binary string: G\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\scfilter.sys.mui |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\System32\tbssvc.dllSTE |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnlx002.catp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Drivers-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: F\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\usb.inf_locp |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\NV_AGP.SYSH |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Modem-Drivers-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.catH |
Source: tasksche.exe.0.dr | Binary string: `\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat |
Source: tasksche.exe.0.dr | Binary string: I\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\lltdio.inf_locp |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\DriverStore\en-USC |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.inip |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\advpack.dll |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\ncobjapi.dllp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Sensors-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\ProgramData\Avg\log\AV16\history.xml |
Source: tasksche.exe.0.dr | Binary string: A\Device\HarddiskVolume2\ProgramData\Avg\AV\Chjw\avgpsi.db-journal |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\msdsm.sysh |
Source: tasksche.exe.0.dr | Binary string: 6\Device\HarddiskVolume2\Windows\System32\sqlceqp30.dll |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnbr00a.cat |
Source: tasksche.exe.0.dr | Binary string: /\Device\HarddiskVolume2\Windows\inf\netserv.PNFTMP8p |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-HomeBasicEdition-wrapper~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: /\Device\HarddiskVolume2\Windows\inf\volsnap.PNFR07 |
Source: tasksche.exe.0.dr | Binary string: `\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows~p |
Source: tasksche.exe.0.dr | Binary string: F\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\volmgrx.sys.muip |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Server-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\HdAudio.sysr |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_KB976932~31bf3856ad364e35~x86~~6.1.0.17514.catlum |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WUClient-SelfUpdate-Aux-AuxComp~31bf3856ad364e35~x86~ru-RU~7.6.7600.320.cat |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\netsstpt.inf_loc |
Source: tasksche.exe.0.dr | Binary string: E\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\AMDAGP.SYS.mui |
Source: tasksche.exe.0.dr | Binary string: X\Device\HarddiskVolume2\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}t$p |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnrc005.catp |
Source: tasksche.exe.0.dr | Binary string: G\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\GAGP30KX.SYS.mui@p |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\VMBusHID.sys |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnca00d.cat |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnep002.catp |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnca00c.catGQ |
Source: tasksche.exe.0.dr | Binary string: h\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\evbdx.sysskV |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\asyncmac.sys |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\iaStorV.sysr* |
Source: tasksche.exe.0.dr | Binary string: g\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Roaming\AVG\AV\cfgall\fixcfg.lockc |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Encoder-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: c\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\log\av16\avgemc.log |
Source: tasksche.exe.0.dr | Binary string: O\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe5E |
Source: tasksche.exe.0.dr | Binary string: +\Device\HarddiskVolume2\Windows\System32\ruIE |
Source: tasksche.exe.0.dr | Binary string: 2\Device\HarddiskVolume2\Windows\System32\wbem\Logs856p |
Source: tasksche.exe.0.dr | Binary string: >\Device\HarddiskVolume2\Windows\System32\drivers\mshidkmdf.sysA |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\mrxdav.sysD |
Source: tasksche.exe.0.dr | Binary string: q\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\BrSerWdm.sys |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-UltimateEdition~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\HdAudio.sysd |
Source: tasksche.exe.0.dr | Binary string: >\Device\HarddiskVolume2\Windows\servicing\TrustedInstaller.exeAP7PDC |
Source: tasksche.exe.0.dr | Binary string: k\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Server-Help-Package.ClientUltimate~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1_for_KB976902~31bf3856ad364e35~x86~~6.1.1.17514.catCp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WindowsFoundation-LanguagePack-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.catid4 |
Source: tasksche.exe.0.dr | Binary string: h\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\log\av16\avgidpdrv.log.2H |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Media-Format-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: 1\Device\HarddiskVolume2\Windows\System32\pots.dllp |
Source: tasksche.exe.0.dr | Binary string: G\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: \\Device\HarddiskVolume2\Windows\System32\ru-RU\microsoft-windows-kernel-power-events.dll.mui |
Source: tasksche.exe.0.dr | Binary string: t\Device\HarddiskVolume2\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.inim |
Source: tasksche.exe.0.dr | Binary string: k\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exeta |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-WMIProvider-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat$0p |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\dot3svc.dllPN |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\rdpdr.sysw |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\pnrpauto.dll |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\winusb.sysiv |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\gpscript.dll |
Source: tasksche.exe.0.dr | Binary string: G\Device\HarddiskVolume2\Windows\System32\config\systemprofile\Favorites3 |
Source: tasksche.exe.0.dr | Binary string: 1\Device\HarddiskVolume2\Windows\System32\qmgr.dll |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_KB976932~31bf3856ad364e35~x86~~6.1.0.17514.cat |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnky007.catp |
Source: tasksche.exe.0.dr | Binary string: @\Device\HarddiskVolume2\Windows\Prefetch\SVCHOST.EXE-007FEA55.pf |
Source: tasksche.exe.0.dr | Binary string: S\Device\HarddiskVolume2\Program Files\Common Files\AV\avast! Antivirus\userdata.cab0_TS |
Source: tasksche.exe.0.dr | Binary string: A\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnca00y.catp |
Source: tasksche.exe.0.dr | Binary string: H\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc |
Source: tasksche.exe.0.dr | Binary string: |\Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.iniop |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\lpremove.exep |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\hidbth.sys<\ |
Source: tasksche.exe.0.dr | Binary string: >\Device\HarddiskVolume2\Windows\System32\gatherNetworkInfo.vbs1 |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Server-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat\ |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\djsvs.sysD |
Source: tasksche.exe.0.dr | Binary string: O\Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\AppData\Local\Temp |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\vmbus.sys |
Source: tasksche.exe.0.dr | Binary string: S\Device\HarddiskVolume3\$RECYCLE.BIN\S-1-5-21-1870734524-1274666089-2119431859-1000H |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-CodecPack-Basic-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnhp002.catWp |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnbr004.catH |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-BusinessScanning-Feature-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\vms3cap.sys |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\ru-RU\rascfg.dll.mui |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Tuner-Drivers-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ICM-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: U\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\User Profile Service |
Source: tasksche.exe.0.dr | Binary string: 7\Device\HarddiskVolume2\Program Files\AVG\Av\avgwsc.exep |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\isapnp.sys |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\BrUsbMdm.sys |
Source: tasksche.exe.0.dr | Binary string: D\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\umbus.sys.mui |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\IPMIDrv.sys |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\ru-RU\erofflps.txt |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\adpu320.sys |
Source: tasksche.exe.0.dr | Binary string: `\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem3.CATo |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_KB976902_RTM~31bf3856ad364e35~x86~~6.1.1.17514.cat |
Source: tasksche.exe.0.dr | Binary string: F\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\System32\wersvc.dll |
Source: tasksche.exe.0.dr | Binary string: >\Device\HarddiskVolume2\Users\Public\Desktop\Google Chrome.lnk |
Source: tasksche.exe.0.dr | Binary string: ?\Device\HarddiskVolume2\Windows\System32\drivers\Synth3dVsc.sys |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnbr004.catp |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\System32\Defrag.exe |
Source: tasksche.exe.0.dr | Binary string: A\Device\HarddiskVolume2\Windows\Prefetch\AVGUIRNX.EXE-006CD133.pfp |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\inf\netvwififlt.PNFF4 |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-NFS-ClientSKU-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\aliide.sys |
Source: tasksche.exe.0.dr | Binary string: 6\Device\HarddiskVolume2\Windows\System32\werconcpl.dll |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\UAGP35.SYSt |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\mstee.sysP |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GPUPipeline-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.catPROTp |
Source: tasksche.exe.0.dr | Binary string: D\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\PLA_S |
Source: tasksche.exe.0.dr | Binary string: V\Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb |
Source: tasksche.exe.0.dr | Binary string: I\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\NetTrace |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\mstee.sys |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\netnwifi.inf_loc |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnbr006.cat |
Source: tasksche.exe.0.dr | Binary string: C\Device\HarddiskVolume2\Program Files\Internet Explorer\ieproxy.dll |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\storvsc.sys |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\sfloppy.sysH |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Program Files\AVG\UiDll\2623\cef.pakp |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnts002.catp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~x86~en-US~8.0.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: r\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaDataI |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Disk-Diagnosis-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: J\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\ndisuio.inf_locp |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnep00f.catCp |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\AMDAGP.SYS.pdap |
Source: tasksche.exe.0.dr | Binary string: 6\Device\HarddiskVolume2\ProgramData\Avg\AV\DB\stats.db\/ |
Source: tasksche.exe.0.dr | Binary string: `\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem9.CATpx |
Source: tasksche.exe.0.dr | Binary string: >\Device\HarddiskVolume2\Windows\servicing\TrustedInstaller.exe |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\BrFiltUp.sys |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Personalization-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\Performance\WinSAT\DataStore |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\System32\SndVol.exep |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\ql40xx.sys\ |
Source: tasksche.exe.0.dr | Binary string: \\Device\HarddiskVolume2\ProgramData\Microsoft\Windows\Start Menu\Programs\Remote Access Hostb |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-StarterEdition-wrapper~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Common-Modem-Drivers-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-MobilePC-Client-Premium-Package~31bf3856ad364e35~x86~~6.1.7601.17514.catdp |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\WcsPlugInService.dll |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\TsUsbGD.sys$ |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\System32\sdrsvc.dll |
Source: tasksche.exe.0.dr | Binary string: J\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\usbport.inf_loc |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-EnterpriseEdition-wrapper~31bf3856ad364e35~x86~~6.1.7601.17514.catHp |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\UAGP35.SYS |
Source: tasksche.exe.0.dr | Binary string: X\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\NetworkAccessProtectionPM |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Xps-Foundation-Client-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnhp003.catC |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Server-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\cmdide.sys |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Sidebar-Killbits-SDP-Package~31bf3856ad364e35~x86~~6.1.7601.17514.catH |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnky004.cat\ |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Server-Package~31bf3856ad364e35~x86~~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: Z\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ClipsInTheLibrary-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\lsi_fc.sysX |
Source: tasksche.exe.0.dr | Binary string: ~\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0\Icon Files |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\megasas.sysW |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\ql2300.sys |
Source: tasksche.exe.0.dr | Binary string: J\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\netrast.inf_loc'* |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\log\av16\avg-6ff9b621-270c-4f57-87d7-93687ce43d15.tmpp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_for_KB976933~31bf3856ad364e35~x86~en-US~6.1.7601.17514.cat5E5p |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prngt003.catp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WMI-SNMP-Provider-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: s\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows Media Player NSS\3.0R |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\consent.exe |
Source: tasksche.exe.0.dr | Binary string: R\Device\HarddiskVolume2\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\sffdisk.sys |
Source: tasksche.exe.0.dr | Binary string: 0\Device\HarddiskVolume2\Windows\System32\DXP.dllp |
Source: tasksche.exe.0.dr | Binary string: >\Device\HarddiskVolume2\Windows\SoftwareDistribution\DataStore |
Source: tasksche.exe.0.dr | Binary string: g\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\log\av16\avgns.log.lock |
Source: tasksche.exe.0.dr | Binary string: 8\Device\HarddiskVolume2\Windows\System32\drivers\smb.sys |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\mstee.sysfw\ZZ_ |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Telnet-Client-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cate |
Source: tasksche.exe.0.dr | Binary string: `\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem9.CATmp |
Source: tasksche.exe.0.dr | Binary string: L\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\aitagent.exe |
Source: tasksche.exe.0.dr | Binary string: 1\Device\HarddiskVolume2\ProgramData\Microsoft\RAC |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\RacEngn.dllPU |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\log\av16\avg-6ff9b621-270c-4f57-87d7-93687ce43d15.tmp$ |
Source: tasksche.exe.0.dr | Binary string: V\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\Media Center\Extender |
Source: tasksche.exe.0.dr | Binary string: b\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\log\av16\avgns.logUSB4 |
Source: tasksche.exe.0.dr | Binary string: ,\Device\HarddiskVolume2\Windows\System32\wfpip |
Source: tasksche.exe.0.dr | Binary string: ^\Device\HarddiskVolume2\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\storvsc.sys2 |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\inf\compositebus.PNFp |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\lsi_fc.sys( |
Source: tasksche.exe.0.dr | Binary string: /\Device\HarddiskVolume2\Windows\inf\machine.PNF |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-CommandLineTools-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: I\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\Registry |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.dirp |
Source: tasksche.exe.0.dr | Binary string: I\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\netip6.inf_loc |
Source: tasksche.exe.0.dr | Binary string: >\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\mspqm.sysP5 |
Source: tasksche.exe.0.dr | Binary string: G\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\vdrvroot.sys.mui |
Source: tasksche.exe.0.dr | Binary string: )\Device\HarddiskVolume2\Windows\Resources |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\megasas.sys3 |
Source: tasksche.exe.0.dr | Binary string: @\Device\HarddiskVolume2\Windows\System32\appidcertstorecheck.exe |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\IPSECSVC.DLL |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnbr008.cat |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnca00b.cat |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\UAGP35.SYS\W |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\ipnat.sys |
Source: tasksche.exe.0.dr | Binary string: 9\Device\HarddiskVolume2\Windows\System32\catroot2\edb.logp |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\usbohci.sys |
Source: tasksche.exe.0.dr | Binary string: ]\Device\HarddiskVolume2\Windows\System32\winevt\Logs\Microsoft-Windows-NCSI%4Operational.evtxp |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\adp94xx.sysLP |
Source: tasksche.exe.0.dr | Binary string: b\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WUClient-SelfUpdate-Core~31bf3856ad364e35~x86~~7.6.7600.320.cat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-VirtualPC-USB-RPM-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.catp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.widV |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\GAGP30KX.SYS |
Source: tasksche.exe.0.dr | Binary string: .\Device\HarddiskVolume2\Windows\inf\netip6.PNF |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\SCardSvr.dll |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini& |
Source: tasksche.exe.0.dr | Binary string: V\Device\HarddiskVolume2\Users\ |
Source: tasksche.exe.0.dr | Binary string: D\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\rdbss.sys.mui\p |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\av16\temp\avg-27617c4e-7c1a-491f-b8be-a34d5070ed64.tmp|$hH |
Source: tasksche.exe.0.dr | Binary string: \Device\CdRom0PchSmi |
Source: tasksche.exe.0.dr | Binary string: T\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\av16rp |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnrc003.catp |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\SISAGP.SYSx |
Source: tasksche.exe.0.dr | Binary string: 5\Device\HarddiskVolume2\Windows\System32\timedate.cplp |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\rdpdr.sysl\2 |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnky008.cat |
Source: tasksche.exe.0.dr | Binary string: c\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Local\Avg\log\av16\fixcfg.log |
Source: tasksche.exe.0.dr | Binary string: 0\Device\HarddiskVolume2\Windows\System32\wmp.dll |
Source: tasksche.exe.0.dr | Binary string: h\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookiesp |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnca00h.cat |
Source: tasksche.exe.0.dr | Binary string: I\Device\HarddiskVolume2\Windows\System32\DriverStore\ru-RU\netip6.inf_locp |
Source: tasksche.exe.0.dr | Binary string: C\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\ntfs.sys.mui |
Source: tasksche.exe.0.dr | Binary string: 3\Device\HarddiskVolume2\Windows\System32\FXSSVC.exe |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\dxgkrnl.sys |
Source: tasksche.exe.0.dr | Binary string: r\Device\HarddiskVolume2\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLsCPU1 |
Source: tasksche.exe.0.dr | Binary string: 1\Device\HarddiskVolume2\Windows\Temp\CR_6DDFF.tmpp |
Source: tasksche.exe.0.dr | Binary string: 0\Device\HarddiskVolume2\Windows\System32\url.dll |
Source: tasksche.exe.0.dr | Binary string: \Device\Harddisk0\DR0p |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\nvraid.sys=\( |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Editions-Client-Package~31bf3856ad364e35~x86~~6.1.7601.17514.catrs\p |
Source: tasksche.exe.0.dr | Binary string: 8\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft$Hp |
Source: tasksche.exe.0.dr | Binary string: E\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\amdppm.sys.mui |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\tdtcp.sys|$P@ |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnep00d.catp |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\SISAGP.SYS8 |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\HdAudio.sys\/ |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\SISAGP.SYS3 |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\VIAAGP.SYS. |
Source: tasksche.exe.0.dr | Binary string: p\Device\HarddiskVolume2\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtxxpp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Indexing-Service-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat\$p |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\flpydisk.sys |
Source: tasksche.exe.0.dr | Binary string: K\Device\HarddiskVolume2\ProgramData\Microsoft\RAC\StateData\RacDatabase.sdf |
Source: tasksche.exe.0.dr | Binary string: 2\Device\HarddiskVolume2\Windows\System32\Tasks\WPDGtn |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\elxstor.sysV |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SampleContent-Ringtones-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: 9\Device\HarddiskVolume2\Program Files\AVG\Av\avgmfapx.exep |
Source: tasksche.exe.0.dr | Binary string: F\Device\HarddiskVolume2\Windows\Prefetch\SEARCHINDEXER.EXE-4A6353B9.pfH |
Source: tasksche.exe.0.dr | Binary string: a\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem12.CAT |
Source: tasksche.exe.0.dr | Binary string: F\Device\HarddiskVolume2\Program Files\AVG Web TuneUp\BundleInstall.exe |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnrc004.cat |
Source: tasksche.exe.0.dr | Binary string: ?\Device\HarddiskVolume2\Program Files\AVG\UiDll\2623\icudtl.datp |
Source: tasksche.exe.0.dr | Binary string: <\Device\HarddiskVolume2\Windows\System32\drivers\elxstor.sys\ |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\ipnat.sys4 |
Source: tasksche.exe.0.dr | Binary string: 0\Device\HarddiskVolume2\Windows\inf\nettcpip.PNFS |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\MegaSR.sysDC2 |
Source: tasksche.exe.0.dr | Binary string: [\Device\HarddiskVolume2\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatformU3 |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\umpass.sys |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\ql40xx.sys |
Source: tasksche.exe.0.dr | Binary string: =\Device\HarddiskVolume2\Windows\System32\drivers\lsi_scsi.sys |
Source: tasksche.exe.0.dr | Binary string: >\Device\HarddiskVolume2\Windows\System32\drivers\fsdepends.sysd0`p |
Source: tasksche.exe.0.dr | Binary string: d\Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\prnca00h.catSp |
Source: tasksche.exe.0.dr | Binary string: p\Device\HarddiskVolume2\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SearchEngine-Client-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat |
Source: tasksche.exe.0.dr | Binary string: |\Device\HarddiskVolume2\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.datp |
Source: tasksche.exe.0.dr | Binary string: \Device\HarddiskVolume2\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-TerminalServices-UsbRedirector-Package~31bf3856ad364e35~x86~ru-RU~6.1.7601.17514.cat: |
Source: tasksche.exe.0.dr | Binary string: G\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\processr.sys.mui |
Source: tasksche.exe.0.dr | Binary string: C\Device\HarddiskVolume2\Windows\System32\drivers\ru-RU\acpi.sys.mui |
Source: tasksche.exe.0.dr | Binary string: :\Device\HarddiskVolume2\Windows\System32\drivers\djsvs.sys |
Source: tasksche.exe.0.dr | Binary string: ;\Device\HarddiskVolume2\Windows\System32\drivers\nvstor.sys2\ |
Source: tasksche.exe.0.dr | Binary string: 4\Device\HarddiskVolume2\Windows\System32\rasauto.dll_S |