Source: unknown | Process created: C:\Users\user\Desktop\Reminder.exe "C:\Users\user\Desktop\Reminder.exe" |
Source: C:\Users\user\Desktop\Reminder.exe | Process created: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp" /SL5="$40392,1755695,835584,C:\Users\user\Desktop\Reminder.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process created: C:\Users\user\Desktop\Reminder.exe "C:\Users\user\Desktop\Reminder.exe" /VERYSILENT |
Source: C:\Users\user\Desktop\Reminder.exe | Process created: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp" /SL5="$6037A,1755695,835584,C:\Users\user\Desktop\Reminder.exe" /VERYSILENT |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH | find /I "wrsa.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "wrsa.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH | find /I "opssvc.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "opssvc.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | find /I "avastui.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "avastui.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH | find /I "avgui.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "avgui.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH | find /I "nswscsvc.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "nswscsvc.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH | find /I "sophoshealth.exe" |
Source: C:\Users\user\Desktop\Reminder.exe | Process created: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp" /SL5="$40392,1755695,835584,C:\Users\user\Desktop\Reminder.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "sophoshealth.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Users\user\AppData\Local\coigned\Updater.exe "C:\Users\user\AppData\Local\coigned\\Updater.exe" "C:\Users\user\AppData\Local\coigned\\friendliwise.csv" |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process created: C:\Users\user\Desktop\Reminder.exe "C:\Users\user\Desktop\Reminder.exe" /VERYSILENT |
Source: C:\Users\user\Desktop\Reminder.exe | Process created: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp "C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp" /SL5="$6037A,1755695,835584,C:\Users\user\Desktop\Reminder.exe" /VERYSILENT |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH | find /I "wrsa.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH | find /I "opssvc.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "wrsa.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq opssvc.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "opssvc.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | find /I "avastui.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH | find /I "avgui.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH | find /I "nswscsvc.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Windows\System32\cmd.exe "cmd.exe" /C tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH | find /I "sophoshealth.exe" |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process created: C:\Users\user\AppData\Local\coigned\Updater.exe "C:\Users\user\AppData\Local\coigned\\Updater.exe" "C:\Users\user\AppData\Local\coigned\\friendliwise.csv" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "avgui.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq nswscsvc.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "nswscsvc.exe" |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\find.exe find /I "sophoshealth.exe" |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c ping -n 5 127.0.0.1 >nul && updater.exe C:\ProgramData\\ZPrVgH71.a3x && del C:\ProgramData\\ZPrVgH71.a3x |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping -n 5 127.0.0.1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\coigned\Updater.exe updater.exe C:\ProgramData\\ZPrVgH71.a3x |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c ping -n 5 127.0.0.1 >nul && updater.exe C:\ProgramData\\ZPrVgH71.a3x && del C:\ProgramData\\ZPrVgH71.a3x |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping -n 5 127.0.0.1 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\coigned\Updater.exe updater.exe C:\ProgramData\\ZPrVgH71.a3x |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Source: C:\Users\user\Desktop\Reminder.exe | Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\Reminder.exe | Section loaded: apphelp.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: mpr.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: version.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: winhttp.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: uxtheme.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: wtsapi32.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: winsta.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: textinputframework.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: coreuicomponents.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: coremessaging.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: ntmarta.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: shfolder.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: rstrtmgr.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: ncrypt.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: ntasn1.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: windows.storage.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: wldp.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: propsys.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: edputil.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: urlmon.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: iertutil.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: srvcli.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: netutils.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: windows.staterepositoryps.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: sspicli.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: appresolver.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: bcp47langs.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: slc.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: userenv.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: sppc.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: onecorecommonproxystub.dll |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Section loaded: onecoreuapcommonproxystub.dll |
Source: C:\Users\user\Desktop\Reminder.exe | Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\Reminder.exe | Section loaded: apphelp.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: mpr.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: version.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: winhttp.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: uxtheme.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: wtsapi32.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: winsta.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: textinputframework.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: coreuicomponents.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: coremessaging.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: ntmarta.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: coremessaging.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: shfolder.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: rstrtmgr.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: ncrypt.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: ntasn1.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: textshaping.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: windows.storage.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: wldp.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: sspicli.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: dwmapi.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: sfc.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: sfc_os.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: explorerframe.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Section loaded: apphelp.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll |
Source: C:\Windows\System32\find.exe | Section loaded: ulib.dll |
Source: C:\Windows\System32\find.exe | Section loaded: fsutilext.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: wsock32.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: version.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: winmm.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: mpr.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: wininet.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: iphlpapi.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: userenv.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: uxtheme.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: cryptsp.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: rsaenh.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: cryptbase.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: windows.storage.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: wldp.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: profapi.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: propsys.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: edputil.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: urlmon.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: iertutil.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: srvcli.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: netutils.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: windows.staterepositoryps.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: sspicli.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: appresolver.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: bcp47langs.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: slc.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: sppc.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: onecorecommonproxystub.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: onecoreuapcommonproxystub.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: pcacli.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: sfc_os.dll |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: iphlpapi.dll |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: winnsi.dll |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: mswsock.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: wsock32.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: version.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: winmm.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: mpr.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: wininet.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: iphlpapi.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: userenv.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: uxtheme.dll |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wininet.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: sspicli.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: iertutil.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: windows.storage.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: wldp.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: profapi.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: ondemandconnroutehelper.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winhttp.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: mswsock.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: iphlpapi.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: winnsi.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: urlmon.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: srvcli.dll |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Section loaded: netutils.dll |
Source: C:\Users\user\Desktop\Reminder.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-H0PE8.tmp\Reminder.tmp | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Reminder.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-KHK92.tmp\Reminder.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\coigned\Updater.exe | Process information set: NOOPENFILEERRORBOX |