Source: |
Binary string: pnidui.pdbUGP source: rundll32.exe, 00000006.00000002.1854222306.00007FFDFB767000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \ICS_Release\Setup.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \magadan21\loader\objfre_wxp_x86\i386\Loader.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \work\urlgl\driver2\objfre_wxp_x86\i386\MekeAttManage.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\SearchRecover.pdb( source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: "0\7to\apphelp\Release\injectdll.pdbR source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \Release\Wallpaper.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\IrCS_Release\Setup.pdb/ source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \SearchRecover.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\BLDService.pdb6 source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\ICS_Release\Setup.pdb9 source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \IrCS_Release\Setup.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \bbcomm.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 90\work\urlgl\driver2\objfre_wxp_x86\i386\MekeAttManage.pdb= source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\bbhelper.pdb$ source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\setupplugins.pdb& source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \bbhelper.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \WallpaperInstall\release\WallpaperInstall.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0 \magadan21\loader\objfre_wxp_x86\i386\Loader.pdb% source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \Release\Wallpaper.pdbG source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \setupplugins.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\bbcomm.pdb2 source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \Release\Laban.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\weiduan.pdb+ source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \BLDService.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\ExtWatcher.pdbB source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: pnidui.pdb source: rundll32.exe, 00000006.00000002.1854222306.00007FFDFB767000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \weiduan.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: .0\WallpaperInstall\release\WallpaperInstall.pdbb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \ExtWatcher.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \Release\Laban.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \7to\apphelp\Release\injectdll.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\pnidui.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\biwinrt.dllore.dllng |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\zh-CN\ntdll.dll.mui.0r |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\InputMethod\CHS\ChsPinyinDM49.lexe.lex\ChsChsPinyinHap_s.lex |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\zh-CN\ndis.sys.mui |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows.old\Windows\WinSxS\Tempe.exee1 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\CloudExperienceHostCommon.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\zh-CN\crypt32.dll.mui |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\SyncCenter.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\winevt\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\stobject.dllprofile; |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\MosStorage.dllll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ucrtbase_clr0400.dllF- |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Program Files (x86)\Mythware\ |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ClipRenew.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows.old\Windows\WinSxS\amd64_microsoft-windows-hvsi-service-shared_31bf3856ad364e35_10.0.19041.906_none_6530c5981102f17fbwere.dat |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\StateRepository.Core.dllllstem32\WindowsPowerShell\v |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\zh-CN\rundll32.exe.mui |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\icuuc.dlles |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\INF\kdnic.PNFrStore\zh-CNcat |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dllrfaceCl |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\ClipSp.sysPCI# |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\WofUtil.dll\EdgeCorei |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\WSDApi.dllcbda2}\0004010 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\Windows.Media.Devices.dllrogramDataPublic=C:\Users\Pu |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\authui.dllllost.exetificados CGN V20P |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\zh-CN\acpi.sys.mui |
Source: AyCnklzHb7.dll |
Binary string: S-1-5-21-582503613-890440277-4174216604-1001\Device\HarddiskVolume3\Windows\System32\GameBarPresenceWriter.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\cscobj.dllxyewy3d8bbwe+ |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll.dllA6 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ProximityServicePal.dlla90-b076-33f57bf4eaa7}\#0}\#KBD |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\servicing\Packages\Microsoft-Windows-WinOcr-Package~31bf3856ad364e35~amd64~zh-CN~10.0.19041.1.mum35~amd64~~10.0.19041.1.mum\3\g95]_F_ |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\zh-CN\processr.sys.mui |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\NcdAutoSetup.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\LogFiles\WMI\IntelA |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\svchost.exeiF |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\mssecflt.sysle |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\ProgramData\Huorong\Sysdiag\wlfile.db-shm |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\D3D12.dll0c75d6}\0008 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SysWOW64\thumbcache.dlls.dlll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\SleepStudyScreenOn |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Users\ |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\servicing\Packages\Microsoft-Windows-TFTP-Client-Package~31bf3856ad364e35~amd64~~10.0.19041.1.mummlep-UqQSqnMp-FI[1].css.pngw |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\SecureTimeAggregator.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\batmeter.dlldll8f69f |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\RTWorkQ.dll3 G30N |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\128.0.2739.79\identity_proxy\internal.identity_helper.exe.manifestD39FCE23AF8F277537F2613.scale-100_ |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\fdPHost.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\RTWorkQ.dllmprofile+ |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\WfNicPnp64.sysnterfaceClass\{97EBAACB-95BD-11D0-A3EA-00A0C9223196}InterfaceClass\{3C4852D6-D47B-4F46-B05E-B5EDC1AA440 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\Windows.Media.Devices.dllON=a503ProgramData=C:\Progra |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\mobsync.exeWERTemp |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows.old\Windows\System32\wbemgmp |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\BitsProxy.dll.dllLL |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\IntelTA.syslas |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SysWOW64\imageres.dlllure.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\zh-CN\mssmbios.sys.mui |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\INF\rt640x64.inforezh-CNcat |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\InputMethod\CHS\ChsPinyinDM49.lex.lexcontrast-white.pngdll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\netcenter.dllftdll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\Microsoft\Protectui |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\appcompat\ProgramsbowsApps |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\zh-CN\cscui.dll.muiat |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\servicing\Packages\Microsoft-Windows-WinOcr-Opt-Package~31bf3856ad364e35~amd64~~10.0.19041.746.mumV\3\g |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\SecureTimeAggregator.dllD$ |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\RTWorkQ.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\wmilib.sysF5-6 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\pcw.sysCA-84AE |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\icu.dllup.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\acpiex.sys1_V |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\dxgiadaptercache.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\RuntimeBroker.exel |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\BitLockerWizardElev.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\Start Menu |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\wbem\wbemess.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\fontgroupsoverride.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\SettingMonitor.dllll6 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\srpapi.dllSLSApps |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\AuthBroker.dll.dllb |
Source: AyCnklzHb7.dll |
Binary string: S-1-5-19\Device\HarddiskVolume3\Windows\System32\svchost.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\WinSxS\Manifests\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_51704e630f46ca5c.manifest |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\AppReadinessimeBroker.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\zh-CN\sxs.dll.muixeL.c |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\InputMethod\CHS\ChsPinyinDM06.lex.CBS_cw5n1h2txyewy\d2d1.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\pnidui.dllkages |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SysWOW64\wmp.dllTempgesTemp7< |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\Windows.UI.Shell.dllApplicationCA2 Root0 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\WPDShServiceObj.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\cscobj.dlldllewywywyti |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\pris\resources.zh-CN.prie7$\Default |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\crypttpmeksvc.dll5FC59 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\shdocvw.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SoftwareDistribution\PostRebootEventCache.V2e\Scheduled Start |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\InprocLogger.dlllf |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\AudioSrvPolicyManager.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\DXCore.dllsicDisplay.sys |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\bitsigd.dlldll.mui |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ProximityServicePal.dll11d2-b082-00a0c91efb8b}\#r#or |
Source: AyCnklzHb7.dll |
Binary string: f\DEVICE\HARDDISKVOLUME3\PROGRAM FILES (X86)\MYTHWARE\ |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\deviceassociation.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\CloudExperienceHostCommon.dllfb-MaxSessions |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\SyncInfrastructure.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SysWOW64\dbghelp.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\CloudExperienceHostCommon.dllALLUSERSPROFILE=C:\ProgramDataAPPDATA=C:\Windows\system32\config\systemprofile\AppData\RoamingCommonPr |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\AudioSrvPolicyManager.dllem32;C:\Windows;C:\Windows\Sy |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ProximityServicePal.dll-9409-add3064c0cad}\#color## |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SysWOW64\mlang.dll3F8646} |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\zh-CN\stobject.dll.mui |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\batmeter.dll.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Program Files\desktop.inidlle.dlls% |
Source: AyCnklzHb7.dll |
Binary string: ..\DEVICE\HARDDISKVOLUME31Y |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\drivers\SgrmAgent.sys_9BC8CompatibleId\PCI#VEN_8086&DEV_A382CompatibleId\PCI#VEN_8086&DEV_A396CompatibleId\PCI#VEN_8086&DEV_A3A1Compatiblenterface |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\dsreg.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrccache\en-US\ec4d5fdd-aa12-400f-83e2-7b0ea6023eb7\SoftwareInfo\SoftwareInfo.xml |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll4B3B-B7 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ncryptprov.dlls.dllatcho |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\RuntimeBroker.exe.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\ProgramData\Microsoft\Networkte\Log9f |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\StateRepository.Core.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\webservices.dll}\0004 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\wbemed.exebled.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\wbem\AutoRecover\0004 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ktmw32.dllShell.dllt |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\zh-CN\sxs.dll.muiL.0" |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\128.0.2739.67\pwahelper.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\oobe\msoobedui.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\iphlpsvc.dllves.dllCS |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\srchadmin.dllwsAppse |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\Edge\Application\128.0.2739.79\Trust Protection Lists\Mu:$DSC:$LOGGED_UTILITY_STREAMBLE_ |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ActionCenter.dllLL |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\explorer.exeg.dlllework.dll)0 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\pris\resources.zh-CN.prial_cw5n1h2txyewyies |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\SettingMonitor.dllt |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\mobsync.exeWER\Tempg |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\aadWamExtension.dllll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\EdgeManager.dll.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\pris\resources.zh-CN.pri-3e7$\Default |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AAD.Core.dllService-0x0-3e7$\DefaultD |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\bcastdvr\KnownGameList.binllSzo |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\bcastdvrzh-HANSUI.Shell.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Program Files (x86)\Huorong\Sysdiag\bin\wsctrlsvc.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB2808e.cdf-ms9a3ceb6c.manifestt |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\wbem\wmiutils.dll008 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\128.0.2739.79\libGLESv2.dll:WofCompressedData |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\pnidui.dllkagesR |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ncryptsslp.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\InputMethod\CHS\ChsPinyinFamilyName.lex\ChsChsPinyinHap_s.lex |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\Windows.UI.Shell.dll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows.old\ProgramDatas (x86)ftpsl |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\Windows.Media.Devices.dllerationId |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\zh-CN\twinui.dll.mui6 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\ActionCenter.dllester0 |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\SysWOW64\wscapi.dlllrt.dlll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\aadWamExtension.dll1pn |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\SecureTimeAggregator.dllSystemRoot=C:\WindowsSystemDrive=C:WinDir=C:\WindowsCommonProgramFile |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\Logs\CBS\CBS.logSlller.exe |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\StateRepository.Core.dllem32\config\systemprofilewind |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\AudioSrvPolicyManager.dllerationId |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\msftedit.dlle\common |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28\Policy.vpolSysTray |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\cscobj.dllysdiag\bin |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\icuin.dllws\wfp |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\fdWSD.dllI.dllll |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\MCCSPal.dllll.mui |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\ProgramData\Huorong\Sysdiag\db\behav.db |
Source: AyCnklzHb7.dll |
Binary string: \Device\HarddiskVolume3\Windows\System32\zh-CN\kernel32.dll.mui |
Source: unknown |
Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\AyCnklzHb7.dll" |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\AyCnklzHb7.dll",#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\AyCnklzHb7.dll |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\AyCnklzHb7.dll",#1 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\AyCnklzHb7.dll,DllCanUnloadNow |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\AyCnklzHb7.dll,DllGetClassObject |
|
Source: C:\Windows\System32\rundll32.exe |
Process created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 7448 -s 420 |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\AyCnklzHb7.dll,DllRegisterServer |
|
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\AyCnklzHb7.dll",#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\AyCnklzHb7.dll |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\AyCnklzHb7.dll,DllCanUnloadNow |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\AyCnklzHb7.dll,DllGetClassObject |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\AyCnklzHb7.dll,DllRegisterServer |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\AyCnklzHb7.dll",#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Section loaded: mobilenetworking.dll |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\loaddll64.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: aclayers.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: sfc.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: mobilenetworking.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: |
Binary string: pnidui.pdbUGP source: rundll32.exe, 00000006.00000002.1854222306.00007FFDFB767000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \ICS_Release\Setup.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \magadan21\loader\objfre_wxp_x86\i386\Loader.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \work\urlgl\driver2\objfre_wxp_x86\i386\MekeAttManage.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\SearchRecover.pdb( source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: "0\7to\apphelp\Release\injectdll.pdbR source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \Release\Wallpaper.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\IrCS_Release\Setup.pdb/ source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \SearchRecover.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\BLDService.pdb6 source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\ICS_Release\Setup.pdb9 source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \IrCS_Release\Setup.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \bbcomm.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 90\work\urlgl\driver2\objfre_wxp_x86\i386\MekeAttManage.pdb= source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\bbhelper.pdb$ source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\setupplugins.pdb& source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \bbhelper.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \WallpaperInstall\release\WallpaperInstall.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0 \magadan21\loader\objfre_wxp_x86\i386\Loader.pdb% source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \Release\Wallpaper.pdbG source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \setupplugins.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\bbcomm.pdb2 source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \Release\Laban.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\weiduan.pdb+ source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \BLDService.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: 0\ExtWatcher.pdbB source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: pnidui.pdb source: rundll32.exe, 00000006.00000002.1854222306.00007FFDFB767000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \weiduan.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: .0\WallpaperInstall\release\WallpaperInstall.pdbb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \ExtWatcher.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \Release\Laban.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: |
Binary string: \7to\apphelp\Release\injectdll.pdb source: rundll32.exe, 00000006.00000002.1854261533.00007FFDFB7C1000.00000002.00000001.01000000.00000003.sdmp, AyCnklzHb7.dll |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware Virtual USB Mouse |
Source: Amcache.hve.9.dr |
Binary or memory string: vmci.syshbin |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware, Inc. |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware20,1hbin@ |
Source: Amcache.hve.9.dr |
Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563 |
Source: Amcache.hve.9.dr |
Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.9.dr |
Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.9.dr |
Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.9.dr |
Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev |
Source: Amcache.hve.9.dr |
Binary or memory string: c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.9.dr |
Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.9.dr |
Binary or memory string: vmci.sys |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0 |
Source: Amcache.hve.9.dr |
Binary or memory string: vmci.syshbin` |
Source: Amcache.hve.9.dr |
Binary or memory string: \driver\vmci,\driver\pci |
Source: Amcache.hve.9.dr |
Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware20,1 |
Source: Amcache.hve.9.dr |
Binary or memory string: Microsoft Hyper-V Generation Counter |
Source: Amcache.hve.9.dr |
Binary or memory string: NECVMWar VMware SATA CD00 |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware Virtual disk SCSI Disk Device |
Source: Amcache.hve.9.dr |
Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom |
Source: Amcache.hve.9.dr |
Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk |
Source: Amcache.hve.9.dr |
Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware PCI VMCI Bus Device |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware VMCI Bus Device |
Source: Amcache.hve.9.dr |
Binary or memory string: VMware Virtual RAM |
Source: Amcache.hve.9.dr |
Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1 |
Source: Amcache.hve.9.dr |
Binary or memory string: vmci.inf_amd64_68ed49469341f563 |