Source: C:\Windows\SysWOW64\mspaint.exe |
File created: C:\Windows\Debug\WIA |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
File read: C:\Users\desktop.ini |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Jump to behavior |
Source: classification engine |
Classification label: clean1.winPNG@1/1@0/0 |
Source: C:\Windows\SysWOW64\mspaint.exe |
File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL |
Jump to behavior |
Source: Window Recorder |
Window detected: More than 3 window changes detected |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Process information queried: ProcessInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\mspaint.exe |
Queries volume information: C:\Users\user\Desktop\7ASw97uLwOWnId-4R23XxVbAzQ0mid1ESUy4KWXADfo.png VolumeInformation |
Jump to behavior |