Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ecx, 0Dh |
3_2_6D0D9D00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ebp, edi |
3_2_6D0B2F60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ebp, edi |
3_2_6D0B2F66 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ebp, 0Dh |
3_2_6D0D89B0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov dword ptr [esp], edx |
3_2_6D0CCAC0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ecx, dword ptr [esp+5Ch] |
3_2_6D11E520 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ecx, 0Dh |
10_2_6D0D9D00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ebp, edi |
10_2_6D0B2F60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ebp, edi |
10_2_6D0B2F66 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ebp, 0Dh |
10_2_6D0D89B0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov dword ptr [esp], edx |
10_2_6D0CCAC0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ecx, dword ptr [esp+5Ch] |
10_2_6D11E520 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ecx, 0Dh |
12_2_6D069D00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ebp, edi |
12_2_6D042F66 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ebp, edi |
12_2_6D042F60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then shr ebp, 0Dh |
12_2_6D0689B0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov dword ptr [esp], edx |
12_2_6D05CAC0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4x nop then mov ecx, dword ptr [esp+5Ch] |
12_2_6D0AE520 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0C7D30 |
3_2_6D0C7D30 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0D8D70 |
3_2_6D0D8D70 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0BBDAF |
3_2_6D0BBDAF |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0ECDA0 |
3_2_6D0ECDA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0DAC60 |
3_2_6D0DAC60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0B2F60 |
3_2_6D0B2F60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0B2F66 |
3_2_6D0B2F66 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0EDFA0 |
3_2_6D0EDFA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0E5FA0 |
3_2_6D0E5FA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0D2FF0 |
3_2_6D0D2FF0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D124E20 |
3_2_6D124E20 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D129970 |
3_2_6D129970 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0BC9C0 |
3_2_6D0BC9C0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D11E9C0 |
3_2_6D11E9C0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0DC9D0 |
3_2_6D0DC9D0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D10F892 |
3_2_6D10F892 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0DBA10 |
3_2_6D0DBA10 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D11DA50 |
3_2_6D11DA50 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D127A70 |
3_2_6D127A70 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D11E520 |
3_2_6D11E520 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0B3580 |
3_2_6D0B3580 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D1275E0 |
3_2_6D1275E0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D129490 |
3_2_6D129490 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0DD485 |
3_2_6D0DD485 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0DB4A0 |
3_2_6D0DB4A0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D128720 |
3_2_6D128720 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0C5780 |
3_2_6D0C5780 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0C0790 |
3_2_6D0C0790 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0F6690 |
3_2_6D0F6690 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0DA6F0 |
3_2_6D0DA6F0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D108110 |
3_2_6D108110 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0D6100 |
3_2_6D0D6100 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D135170 |
3_2_6D135170 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D11E1F0 |
3_2_6D11E1F0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D11D030 |
3_2_6D11D030 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0D1030 |
3_2_6D0D1030 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0DC060 |
3_2_6D0DC060 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0DC3C0 |
3_2_6D0DC3C0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D0B9240 |
3_2_6D0B9240 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0C7D30 |
10_2_6D0C7D30 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0D8D70 |
10_2_6D0D8D70 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0BBDAF |
10_2_6D0BBDAF |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0ECDA0 |
10_2_6D0ECDA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0DAC60 |
10_2_6D0DAC60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0B2F60 |
10_2_6D0B2F60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0B2F66 |
10_2_6D0B2F66 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0EDFA0 |
10_2_6D0EDFA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0E5FA0 |
10_2_6D0E5FA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0D2FF0 |
10_2_6D0D2FF0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D124E20 |
10_2_6D124E20 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D129970 |
10_2_6D129970 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0BC9C0 |
10_2_6D0BC9C0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D11E9C0 |
10_2_6D11E9C0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0DC9D0 |
10_2_6D0DC9D0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D10F892 |
10_2_6D10F892 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0DBA10 |
10_2_6D0DBA10 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D11DA50 |
10_2_6D11DA50 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D127A70 |
10_2_6D127A70 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D11E520 |
10_2_6D11E520 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0B3580 |
10_2_6D0B3580 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D1275E0 |
10_2_6D1275E0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D129490 |
10_2_6D129490 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0DD485 |
10_2_6D0DD485 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0DB4A0 |
10_2_6D0DB4A0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D128720 |
10_2_6D128720 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0C5780 |
10_2_6D0C5780 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0C0790 |
10_2_6D0C0790 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0F6690 |
10_2_6D0F6690 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0DA6F0 |
10_2_6D0DA6F0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D108110 |
10_2_6D108110 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0D6100 |
10_2_6D0D6100 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D135170 |
10_2_6D135170 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D11E1F0 |
10_2_6D11E1F0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D11D030 |
10_2_6D11D030 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0D1030 |
10_2_6D0D1030 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0DC060 |
10_2_6D0DC060 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0DC3C0 |
10_2_6D0DC3C0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D0B9240 |
10_2_6D0B9240 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D057D30 |
12_2_6D057D30 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D068D70 |
12_2_6D068D70 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D07CDA0 |
12_2_6D07CDA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D04BDAF |
12_2_6D04BDAF |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D06AC60 |
12_2_6D06AC60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D042F66 |
12_2_6D042F66 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D042F60 |
12_2_6D042F60 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D07DFA0 |
12_2_6D07DFA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D075FA0 |
12_2_6D075FA0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D062FF0 |
12_2_6D062FF0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0B4E20 |
12_2_6D0B4E20 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0B9970 |
12_2_6D0B9970 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D04C9C0 |
12_2_6D04C9C0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0AE9C0 |
12_2_6D0AE9C0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D06C9D0 |
12_2_6D06C9D0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D09F892 |
12_2_6D09F892 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D06BA10 |
12_2_6D06BA10 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0ADA50 |
12_2_6D0ADA50 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0B7A70 |
12_2_6D0B7A70 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0AE520 |
12_2_6D0AE520 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D043580 |
12_2_6D043580 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0B75E0 |
12_2_6D0B75E0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D06D485 |
12_2_6D06D485 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0B9490 |
12_2_6D0B9490 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D06B4A0 |
12_2_6D06B4A0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0B8720 |
12_2_6D0B8720 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D055780 |
12_2_6D055780 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D050790 |
12_2_6D050790 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D086690 |
12_2_6D086690 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D06A6F0 |
12_2_6D06A6F0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D066100 |
12_2_6D066100 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D098110 |
12_2_6D098110 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0C5170 |
12_2_6D0C5170 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0AE1F0 |
12_2_6D0AE1F0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D061030 |
12_2_6D061030 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0AD030 |
12_2_6D0AD030 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D06C060 |
12_2_6D06C060 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D06C3C0 |
12_2_6D06C3C0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D049240 |
12_2_6D049240 |
Source: unknown |
Process created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll" |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",#1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\A5r0ypOR77.dll,BarCreate |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",#1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 3040 -s 824 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7020 -s 856 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\A5r0ypOR77.dll,_cgo_dummy_export |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\A5r0ypOR77.dll,acidulavamBelchior |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",BarCreate |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",_cgo_dummy_export |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",acidulavamBelchior |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",ziguezagueemosPiaremos |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 5388 -s 832 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",vitalizeiAglomerarmo |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",renuncieDesembocava |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",refreasseisFestejarieis |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",problematizastesForcaram |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",paralisaremoEmborcaveis |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",lastimareisConfiscara |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",imprevisivelRecondicionaveis |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",franzasDoutrinasses |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",entristecendoControlar |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",ensebaveisApaixonaste |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",desconsiderassemBordejam |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",compensacoesRefroes |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",bacanerrimoEsquecido |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",assentidoRefreava |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",aprendizDesmistificarmo |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\A5r0ypOR77.dll,BarCreate |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\A5r0ypOR77.dll,_cgo_dummy_export |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\A5r0ypOR77.dll,acidulavamBelchior |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",BarCreate |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",_cgo_dummy_export |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",acidulavamBelchior |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",ziguezagueemosPiaremos |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",vitalizeiAglomerarmo |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",renuncieDesembocava |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",refreasseisFestejarieis |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",problematizastesForcaram |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",paralisaremoEmborcaveis |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",lastimareisConfiscara |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",imprevisivelRecondicionaveis |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",franzasDoutrinasses |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",entristecendoControlar |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",ensebaveisApaixonaste |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",desconsiderassemBordejam |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",compensacoesRefroes |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",bacanerrimoEsquecido |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",assentidoRefreava |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",aprendizDesmistificarmo |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\A5r0ypOR77.dll",#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 0_2_014803C7 push ebx; retf |
0_2_014803D3 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D118096 pushad ; retf |
3_2_6D118097 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D11808D pushad ; retf |
3_2_6D11808E |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D1173E2 pushad ; ret |
3_2_6D1173E3 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D118096 pushad ; retf |
10_2_6D118097 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D11808D pushad ; retf |
10_2_6D11808E |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D1173E2 pushad ; ret |
10_2_6D1173E3 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 11_2_0443AEDF push ecx; ret |
11_2_0443B428 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0A808D pushad ; retf |
12_2_6D0A808E |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0A8096 pushad ; retf |
12_2_6D0A8097 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0A73E2 pushad ; ret |
12_2_6D0A73E3 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0A73F1 pushad ; ret |
12_2_6D0A73F2 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_0443B4EC push cs; retf |
13_2_0443B985 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_0443B4FC push cs; retf |
13_2_0443B985 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 13_2_04480001 push 00000004h; iretd |
13_2_04480393 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 16_2_0543AEE2 push ebx; retf |
16_2_0543AEF6 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 16_2_0543AF1E push esi; ret |
16_2_0543AF27 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 16_2_05480001 push es; ret |
16_2_054803D7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 18_2_04C38F4F push es; ret |
18_2_04C38F52 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 18_2_04C38F3B push es; ret |
18_2_04C38F4A |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 20_2_0503A3DA push 15CE8943h; iretd |
20_2_0503A40F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 21_2_04C38F4F push es; ret |
21_2_04C38F52 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 21_2_04C38F3B push es; ret |
21_2_04C38F4A |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 21_2_04C3A9B9 push esi; ret |
21_2_04C3A9BB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 21_2_04C803BE push 00000022h; retf |
21_2_04C803D4 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 24_2_0543A418 push ecx; iretd |
24_2_0543A438 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 24_2_0543BAAE push esi; retf |
24_2_0543BAAF |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 25_2_0543A91A push edi; retf |
25_2_0543A942 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 27_2_0503B9CA push esp; retf |
27_2_0503B9CB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 27_2_0503AF14 pushfd ; ret |
27_2_0503AF13 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 27_2_0503AEDC pushfd ; ret |
27_2_0503AF13 |
Source: C:\Windows\System32\loaddll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
|
Source: rundll32.exe, 0000001F.00000002.2261161419.0000000002D7A000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll; |
Source: rundll32.exe, 00000016.00000002.2252154580.00000000004AA000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll< |
Source: loaddll32.exe, 00000000.00000002.2265356262.0000000000A2E000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllq |
Source: rundll32.exe, 00000004.00000002.2156162399.000000000329A000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllg |
Source: rundll32.exe, 00000003.00000002.2156228001.000000000327A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000B.00000002.2213462157.000000000086A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.2248101246.0000000002DBA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000E.00000002.2246865013.000000000067A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000010.00000002.2248522596.000000000338A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000013.00000002.2249290831.000000000080A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000014.00000002.2251125196.00000000030DA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000015.00000002.2252025975.0000000000A4A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000017.00000002.2253787761.000000000042A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000018.00000002.2255765049.00000000033CA000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000019.00000002.2258269716.00000000034EA000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: rundll32.exe, 0000000D.00000002.2245871499.00000000007DA000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll# |
Source: rundll32.exe, 00000012.00000002.2248598007.0000000000A7A000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000001B.00000002.2260515894.000000000314A000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllrr |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D1364D0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
3_2_6D1364D0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 3_2_6D1364CC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
3_2_6D1364CC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D1364D0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
10_2_6D1364D0 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 10_2_6D1364CC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
10_2_6D1364CC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0C64CC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
12_2_6D0C64CC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 12_2_6D0C64D0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
12_2_6D0C64D0 |