Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34A3250 Concurrency::details::WorkQueue::IsStructuredEmpty,FindFirstFileW,Concurrency::details::_CriticalNonReentrantLock::_Scoped_lock::~_Scoped_lock,FindNextFileW,FindClose, |
0_2_00007FFDA34A3250 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34A3530 Concurrency::details::WorkQueue::IsStructuredEmpty,FindFirstFileW,Concurrency::details::_CriticalNonReentrantLock::_Scoped_lock::~_Scoped_lock,FindNextFileW,FindClose, |
0_2_00007FFDA34A3530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34DBC74 FindFirstFileExW, |
0_2_00007FFDA34DBC74 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34A3250 Concurrency::details::WorkQueue::IsStructuredEmpty,FindFirstFileW,Concurrency::details::_CriticalNonReentrantLock::_Scoped_lock::~_Scoped_lock,FindNextFileW,FindClose, |
3_2_00007FFDA34A3250 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34A3530 Concurrency::details::WorkQueue::IsStructuredEmpty,FindFirstFileW,Concurrency::details::_CriticalNonReentrantLock::_Scoped_lock::~_Scoped_lock,FindNextFileW,FindClose, |
3_2_00007FFDA34A3530 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34DBC74 FindFirstFileExW, |
3_2_00007FFDA34DBC74 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34E03E8 |
0_2_00007FFDA34E03E8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34D0310 |
0_2_00007FFDA34D0310 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34CA0E0 |
0_2_00007FFDA34CA0E0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34CA840 |
0_2_00007FFDA34CA840 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34E2500 |
0_2_00007FFDA34E2500 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34CABD8 |
0_2_00007FFDA34CABD8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34DE8F8 |
0_2_00007FFDA34DE8F8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34D4FE4 |
0_2_00007FFDA34D4FE4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34D2DD8 |
0_2_00007FFDA34D2DD8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34DACC4 |
0_2_00007FFDA34DACC4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34CB26C |
0_2_00007FFDA34CB26C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34CB6A4 |
0_2_00007FFDA34CB6A4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34B16D0 |
0_2_00007FFDA34B16D0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34CF694 |
0_2_00007FFDA34CF694 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34DD680 |
0_2_00007FFDA34DD680 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34D5478 |
0_2_00007FFDA34D5478 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34D5AF8 |
0_2_00007FFDA34D5AF8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34D9B1C |
0_2_00007FFDA34D9B1C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34CFA40 |
0_2_00007FFDA34CFA40 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34D1958 |
0_2_00007FFDA34D1958 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34C9EDC |
0_2_00007FFDA34C9EDC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34E1E64 |
0_2_00007FFDA34E1E64 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34C9CD8 |
0_2_00007FFDA34C9CD8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34DBC74 |
0_2_00007FFDA34DBC74 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34E03E8 |
3_2_00007FFDA34E03E8 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34D0310 |
3_2_00007FFDA34D0310 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34CA0E0 |
3_2_00007FFDA34CA0E0 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34CA840 |
3_2_00007FFDA34CA840 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34E2500 |
3_2_00007FFDA34E2500 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34CABD8 |
3_2_00007FFDA34CABD8 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34DE8F8 |
3_2_00007FFDA34DE8F8 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34D4FE4 |
3_2_00007FFDA34D4FE4 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34D2DD8 |
3_2_00007FFDA34D2DD8 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34DACC4 |
3_2_00007FFDA34DACC4 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34CB26C |
3_2_00007FFDA34CB26C |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34CB6A4 |
3_2_00007FFDA34CB6A4 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34B16D0 |
3_2_00007FFDA34B16D0 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34CF694 |
3_2_00007FFDA34CF694 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34DD680 |
3_2_00007FFDA34DD680 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34D5478 |
3_2_00007FFDA34D5478 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34D5AF8 |
3_2_00007FFDA34D5AF8 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34D9B1C |
3_2_00007FFDA34D9B1C |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34CFA40 |
3_2_00007FFDA34CFA40 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34D1958 |
3_2_00007FFDA34D1958 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34C9EDC |
3_2_00007FFDA34C9EDC |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34E1E64 |
3_2_00007FFDA34E1E64 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34C9CD8 |
3_2_00007FFDA34C9CD8 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34DBC74 |
3_2_00007FFDA34DBC74 |
Source: unknown |
Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\ResPrompt.dll.dll" |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\ResPrompt.dll.dll",#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\ResPrompt.dll.dll |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\ResPrompt.dll.dll",#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\ResPrompt.dll.dll,DllRegisterServer |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\ResPrompt.dll.dll,DllUnregisterServer |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\ResPrompt.dll.dll",#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\ResPrompt.dll.dll |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\ResPrompt.dll.dll,DllRegisterServer |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\ResPrompt.dll.dll,DllUnregisterServer |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\ResPrompt.dll.dll",#1 |
Jump to behavior |
Source: ResPrompt.dll.dll |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: ResPrompt.dll.dll |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: ResPrompt.dll.dll |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: ResPrompt.dll.dll |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: ResPrompt.dll.dll |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: ResPrompt.dll.dll |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: ResPrompt.dll.dll |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: ResPrompt.dll.dll |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: ResPrompt.dll.dll |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: ResPrompt.dll.dll |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: ResPrompt.dll.dll |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Windows\System32\rundll32.exe TID: 5376 |
Thread sleep count: 59 > 30 |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5376 |
Thread sleep count: 36 > 30 |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5376 |
Thread sleep time: -32594s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5376 |
Thread sleep time: -33180s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5376 |
Thread sleep count: 47 > 30 |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 4836 |
Thread sleep count: 56 > 30 |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 4836 |
Thread sleep time: -56000s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 1404 |
Thread sleep count: 47 > 30 |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 1404 |
Thread sleep count: 48 > 30 |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3792 |
Thread sleep time: -33162s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3792 |
Thread sleep time: -39118s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3792 |
Thread sleep time: -35734s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3792 |
Thread sleep time: -36324s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3604 |
Thread sleep time: -35282s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3604 |
Thread sleep time: -32856s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6556 |
Thread sleep time: -35818s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6556 |
Thread sleep time: -33848s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6556 |
Thread sleep time: -52065s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3172 |
Thread sleep time: -34508s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3172 |
Thread sleep time: -37452s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3172 |
Thread sleep time: -36074s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 2760 |
Thread sleep time: -51774s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5052 |
Thread sleep time: -39106s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5052 |
Thread sleep time: -31798s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 1088 |
Thread sleep time: -31664s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 1088 |
Thread sleep time: -35220s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3704 |
Thread sleep time: -35244s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3704 |
Thread sleep time: -38360s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3704 |
Thread sleep time: -34264s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 4920 |
Thread sleep time: -37884s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 4920 |
Thread sleep time: -30772s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 760 |
Thread sleep time: -36104s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 760 |
Thread sleep time: -36758s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6312 |
Thread sleep time: -39580s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 2524 |
Thread sleep time: -30580s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5696 |
Thread sleep time: -36152s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5696 |
Thread sleep time: -33706s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3460 |
Thread sleep time: -39294s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3460 |
Thread sleep time: -31620s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3460 |
Thread sleep time: -31066s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5176 |
Thread sleep time: -38800s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5984 |
Thread sleep time: -32866s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5984 |
Thread sleep time: -32840s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5984 |
Thread sleep time: -35786s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5984 |
Thread sleep time: -36756s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 2760 |
Thread sleep time: -30440s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 2760 |
Thread sleep time: -33066s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6636 |
Thread sleep time: -35226s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3000 |
Thread sleep time: -31784s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3000 |
Thread sleep time: -38608s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3000 |
Thread sleep time: -32382s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3000 |
Thread sleep time: -33722s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3000 |
Thread sleep time: -37340s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6888 |
Thread sleep time: -30710s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 1944 |
Thread sleep time: -38044s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 1944 |
Thread sleep time: -39782s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 4932 |
Thread sleep time: -30410s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 4364 |
Thread sleep time: -39948s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 4364 |
Thread sleep time: -38928s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6076 |
Thread sleep time: -33560s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6076 |
Thread sleep time: -37360s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6076 |
Thread sleep time: -38778s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6076 |
Thread sleep time: -38914s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5028 |
Thread sleep time: -34048s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5028 |
Thread sleep time: -34830s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3200 |
Thread sleep time: -35942s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 4188 |
Thread sleep time: -30908s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3916 |
Thread sleep time: -39524s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 6720 |
Thread sleep time: -31624s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5768 |
Thread sleep time: -32692s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5044 |
Thread sleep time: -36956s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 4952 |
Thread sleep time: -35140s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 5040 |
Thread sleep time: -31034s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3504 |
Thread sleep time: -30466s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe TID: 3924 |
Thread sleep time: -35694s >= -30000s |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34A3250 Concurrency::details::WorkQueue::IsStructuredEmpty,FindFirstFileW,Concurrency::details::_CriticalNonReentrantLock::_Scoped_lock::~_Scoped_lock,FindNextFileW,FindClose, |
0_2_00007FFDA34A3250 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34A3530 Concurrency::details::WorkQueue::IsStructuredEmpty,FindFirstFileW,Concurrency::details::_CriticalNonReentrantLock::_Scoped_lock::~_Scoped_lock,FindNextFileW,FindClose, |
0_2_00007FFDA34A3530 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34DBC74 FindFirstFileExW, |
0_2_00007FFDA34DBC74 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34A3250 Concurrency::details::WorkQueue::IsStructuredEmpty,FindFirstFileW,Concurrency::details::_CriticalNonReentrantLock::_Scoped_lock::~_Scoped_lock,FindNextFileW,FindClose, |
3_2_00007FFDA34A3250 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34A3530 Concurrency::details::WorkQueue::IsStructuredEmpty,FindFirstFileW,Concurrency::details::_CriticalNonReentrantLock::_Scoped_lock::~_Scoped_lock,FindNextFileW,FindClose, |
3_2_00007FFDA34A3530 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34DBC74 FindFirstFileExW, |
3_2_00007FFDA34DBC74 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34C4354 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_00007FFDA34C4354 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34C40A0 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_00007FFDA34C40A0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_00007FFDA34C9238 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_00007FFDA34C9238 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34C4354 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
3_2_00007FFDA34C4354 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34C40A0 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
3_2_00007FFDA34C40A0 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: 3_2_00007FFDA34C9238 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
3_2_00007FFDA34C9238 |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Ping>>//>>Program Manager>>//>>F3723} |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Program Manager |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Ping>>//>>Program Manager>>//>> |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: ClientInfo>>//>>992547/user<-->Windows 10 Pro=19045<-->C:\Windows\system32\rundll32.exe<-->Microsoft Defender Antivirus-<-->1709044087<-->A<-->7/9/2022 23:6 p.m.<-->Program Manager<--> |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: 992547/user<-->Windows 10 Pro=19045<-->C:\Windows\system32\rundll32.exe<-->Microsoft Defender Antivirus-<-->1709044087<-->A<-->7/9/2022 23:6 p.m.<-->Program Manager<--> |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Program ManagerF3723} |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Ping>>//>>Program Manager>>//>>7F3723} |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: ClientInfo>>//>>992547/user<-->Windows 10 Pro=19045<-->C:\Windows\system32\rundll32.exe<-->Microsoft Defender Antivirus-<-->1709044087<-->A<-->7/9/2022 23:6 p.m.<-->Program Manager<-->|G\ |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: ClientInfo>>//>>992547/user<-->Windows 10 Pro=19045<-->C:\Windows\system32\rundll32.exe<-->Microsoft Defender Antivirus-<-->1709044087<-->A<-->7/9/2022 23:6 p.m.<-->Program Manager<-->iGO |
Source: rundll32.exe, 00000004.00000002.4588163768.000002375B338000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: 992547/user<-->Windows 10 Pro=19045<-->C:\Windows\system32\rundll32.exe<-->Microsoft Defender Antivirus-<-->1709044087<-->A<-->7/9/2022 23:6 p.m.<-->Program Manager<-->: 0<--> |
Source: C:\Windows\System32\loaddll64.exe |
Code function: EnumSystemLocalesW, |
0_2_00007FFDA34D40D8 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: GetLocaleInfoW, |
0_2_00007FFDA34D44C4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW, |
0_2_00007FFDA34DEE88 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: EnumSystemLocalesW, |
0_2_00007FFDA34DF2B4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
0_2_00007FFDA34DF34C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: EnumSystemLocalesW, |
0_2_00007FFDA34DF1E4 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: GetLocaleInfoW, |
0_2_00007FFDA34DF79C |
Source: C:\Windows\System32\loaddll64.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_00007FFDA34DF6EC |
Source: C:\Windows\System32\loaddll64.exe |
Code function: GetLocaleInfoW, |
0_2_00007FFDA34DF594 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
0_2_00007FFDA34DF8D0 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: EnumSystemLocalesW, |
3_2_00007FFDA34D40D8 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: GetLocaleInfoW, |
3_2_00007FFDA34D44C4 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW, |
3_2_00007FFDA34DEE88 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: EnumSystemLocalesW, |
3_2_00007FFDA34DF2B4 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
3_2_00007FFDA34DF34C |
Source: C:\Windows\System32\regsvr32.exe |
Code function: EnumSystemLocalesW, |
3_2_00007FFDA34DF1E4 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: GetLocaleInfoW, |
3_2_00007FFDA34DF79C |
Source: C:\Windows\System32\regsvr32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
3_2_00007FFDA34DF6EC |
Source: C:\Windows\System32\regsvr32.exe |
Code function: GetLocaleInfoW, |
3_2_00007FFDA34DF594 |
Source: C:\Windows\System32\regsvr32.exe |
Code function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
3_2_00007FFDA34DF8D0 |