Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#HexBinary |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Text |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-x509-token-profile-1.0#X509SubjectKeyIdentif |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#GSS_Kerberosv5_AP_REQ |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#GSS_Kerberosv5_AP_REQ1510 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#Kerberosv5APREQSHA1 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-rel-token-profile-1.0.pdf#license |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLID |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV1.1 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKey |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKeySHA1 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#ThumbprintSHA1 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-wssecurity-secext-1.1.xsd |
Source: driver.exe, 00000000.00000003.2407882204.00000000079A0000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2427041116.00000000079A2000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000003.2407781130.00000000079A0000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000003.2408090789.00000000079A1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://purl.oen |
Source: driver.exe, 00000000.00000003.2334217727.0000000007991000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://purl.oenM |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/2005/02/trust/spnego#GSS_Wrap |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/2005/02/trust/tlsnego#TLS_Wrap |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2002/12/policy |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/sc |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/sc/dk |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/sc/sct |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/CK/PSHA1 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/Issue |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/Nonce |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/RST/Issue |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/RST/SCT |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/Issue |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/SCT |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/SymmetricKey |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/trust |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/trust/PublicKey |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/trust/SymmetricKey |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/06/addressingex |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/fault |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Aborted |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Commit |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Committed |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Completion |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Durable2PC |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepare |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepared |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/ReadOnly |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Replay |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Rollback |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Volatile2PC |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/fault |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/CreateCoordinationContext |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/CreateCoordinationContextResponse |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/Register |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/RegisterResponse |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/fault |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequence |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/LastMessage |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/SequenceAcknowledgement |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rmd |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/sc |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/sc/dk |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/sc/dk/p_sha1 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/sc/sct |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust#BinarySecret |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/CK/PSHA1 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/Cancel |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/Issue |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/Nonce |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/PublicKey |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT/Cancel |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT/Renew |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Issue |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Cancel |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Renew |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/Renew |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/SymmetricKey |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/spnego |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/tlsnego |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2006/02/addressingidentity |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/ |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/D |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject1 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject1Response |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject1ResponseD |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject2 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject2Response |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject2ResponseD |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject3 |
Source: driver.exe, 00000000.00000002.2412813228.00000000026D5000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject3Response |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject3ResponseD |
Source: driver.exe, 00000000.00000002.2412813228.000000000287B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.o |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AFB000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002AF4000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2417557179.000000000369D000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002C13000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ip.sb/ip |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AFB000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002AF4000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2417557179.000000000369D000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002C13000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AFB000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002AF4000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2417557179.000000000369D000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002C13000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AFB000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002AF4000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2417557179.000000000369D000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002C13000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/users/ |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AFB000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002AF4000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2417557179.000000000369D000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002C13000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AFB000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2417557179.000000000369D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AF4000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002C13000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtabS |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AFB000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002AF4000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2417557179.000000000369D000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002C13000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AFB000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002AF4000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2417557179.000000000369D000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002C13000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: driver.exe, 00000000.00000002.2412813228.0000000002AFB000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002AF4000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2417557179.000000000369D000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.0000000002C13000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: twinui.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: pdh.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: actxprxy.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: ieframe.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.ui.appdefaults.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.ui.immersive.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dui70.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: duser.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: bcp47mrm.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: uianimation.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: tiledatarepository.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: staterepository.core.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.staterepository.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.staterepositorycore.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: mrmcorer.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: appxdeploymentclient.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: thumbcache.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: directmanipulation.dll | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\driver.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEC |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEEL |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXED |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEA |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXER( |
Source: qemu-ga.exe, 00000007.00000002.3451324423.0000000003061000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3451000317.0000000003211000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: YC:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXEE |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEGONS |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START MENU/PROGRAMS/STARTUP/QEMU-GA.EXE.CONFIGG |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011D3000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXET |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEH |
Source: driver.exe, 00000000.00000002.2410417036.0000000000821000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEE |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEF |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIGZ7 |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: \QEMU-GA.EXE |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: $CQYC:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE@\CQ |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\LOCAL\MICROSOFT\CLR_V4.0\USAGELOGS\QEMU-GA.EXE.LOG |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXERING=INTERNET EXPLORERFPS_BROWSER_USER_PROFILE_STRING=DEFAULTHOMEDRIVE=C:HOMEPATH=\USERS\userLOCALAPPDATA=C:\USERS\user\APPDATA\LOCALLOGONSERVER=\\user-PCNUMBER_OF_PROCESSORS=2ONEDRIVE=C:\USERS\user\ONEDRIVEOS=WINDOWS_NTPATH=C:\PROGRAM FILES (X86)\COMMON FILES\ORACLE\JAVA\JAVAPATH;C:\WINDOWS\SYSTEM32;C:\WINDOWS;C:\WINDOWSG7 |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE: |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIGA7 |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE"C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE" C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEWINSTA0\DEFAULTX7 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEW |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.00000000014B0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: "C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE" |
Source: driver.exe, 00000000.00000002.2424787416.0000000006963000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\DESKTOP\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE"C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE" |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEQEMU-GA.EXE |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE:ZONE.IDENTIFIERYD |
Source: driver.exe, 00000000.00000002.2425509068.00000000071A5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \REGISTRY\MACHINE\SOFTWARE\CLASSES\APPLICATIONS\QEMU-GA.EXE |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE! |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START MENU/PROGRAMS/STARTUP/QEMU-GA.EXE.CONFIG |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE.CONFIG |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE} |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START%20MENU\PROGRAMS\STARTUP\QEMU-GA.EXEV |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE' |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014E2000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\LOCALC:\USERS\user\APPDATA\LOCAL\MICROSOFT\CLR_V4.0\USAGELOGS\QEMU-GA.EXE.LOG |
Source: qemu-ga.exe, 00000007.00000002.3451324423.0000000003061000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3451000317.0000000003211000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXE2 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011CE000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEN |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIGM |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START MENU/PROGRAMS/STARTUP/QEMU-GA.EXEIGY7 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE/ |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: $CQYC:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIGE |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE8 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIGG |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\WINDOWS\TEMP\ASLLOG_SHIMDEBUGLOG_QEMU-GA.EXE_7768.TXT L |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: userAPPDATAROAMINGMICROSOFTWINDOWSSTART%20MENUPROGRAMSSTARTUPQEMU-GA.EXE |
Source: driver.exe, 00000000.00000002.2425509068.00000000071A5000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.00000000007EA000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420402313.0000000004D80000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.00000000007A5000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2426725873.0000000007283000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.000000000076E000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448198204.00000000010FA000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407186825.0000000000D82000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXE |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEN@% |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE:ZONE.IDENTIFIERY |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\WINDOWS\TEMP\ASLLOG_APPHELPDEBUG_QEMU-GA.EXE_7768.TXT P |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\WINDOWS\TEMP\ASLLOG_SHIMENGSTATE_QEMU-GA.EXE_7768.TXT |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIGX7 |
Source: driver.exe, 00000000.00000002.2425509068.00000000071A5000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.00000000007EA000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420402313.0000000004D80000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2426725873.0000000007283000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.000000000076E000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEH |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE0\MODULES;C:\PROGRAM FILES (X86)\AUTOIT3\AUTOITXPUBLIC=C:\USERS\PUBLICSESSIONNAME=CONSOLESYSTEMDRIVE=C:SYSTEMROOT=C:\WINDOWSTEMP=C:\USERS\user\APPDATA\LOCAL\TEMPTA |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407230924.0000000000D84000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe.0.dr | Binary or memory string: ORIGINALFILENAMEQEMU-GA.EXE0 |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEY2 |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEQEMU-GA.EXEOWS 10 PRO|C:\WINDOWS|\DEVICE\HARDDISK0\PARTITION320240226161043.462189+060C:\WINDOWS\EXPLORER.EXEC:\WINDOWS\EXPLORER.EXEP3 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:USERSuserAPPDATAROAMINGMICROSOFTWINDOWSSTART%20MENUPROGRAMSSTARTUPQEMU-GA.EXE.CONFIG! |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407230924.0000000000D84000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe.0.dr | Binary or memory string: INTERNALNAMEQEMU-GA.EXEH |
Source: driver.exe, 00000000.00000002.2426725873.0000000007292000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE_ |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIG |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEA7-C |
Source: qemu-ga.exe, 00000007.00000002.3451324423.0000000003061000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3451000317.0000000003211000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXE.CONFIG |
Source: qemu-ga.exe, 00000007.00000002.3451324423.0000000003061000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3451000317.0000000003211000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: `C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIG`_ |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: `POSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: driver.exe, 00000000.00000002.2425509068.00000000071A5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \REGISTRY\MACHINE\SOFTWARE\CLASSES\APPLICATIONS\QEMU-GA.EXEOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START MENU/PROGRAMS/STARTUP/QEMU-GA.EXEE |
Source: driver.exe, 00000000.00000002.2409029084.0000000000410000.00000004.00000020.00040000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE\??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEEN-GBENEN-USMYAPPLICATION.APP |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE0 |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448198204.00000000010FA000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3450183788.00000000013A0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.00000000011D3000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448201010.000000000131A000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.00000000014B0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3450587378.00000000017A0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: driver.exe, 00000000.00000002.2424787416.0000000006963000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEWINSTA0\DEFAULT |
Source: driver.exe, 00000000.00000002.2426725873.0000000007292000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE}2 |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEX7 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\DESKTOP\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE"C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE" C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEWINSTA0\DEFAULTE |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: S/START MENU/PROGRAMS/STARTUP/QEMU-GA.EXE.CONFIGGUU9@P |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407186825.0000000000D82000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe.0.dr | Binary or memory string: <MODULE>QEMU-GAMSCORLIBTHREADCONSOLEREADLINEDEBUGGABLEATTRIBUTECOMVISIBLEATTRIBUTEASSEMBLYTITLEATTRIBUTEASSEMBLYTRADEMARKATTRIBUTETARGETFRAMEWORKATTRIBUTEASSEMBLYFILEVERSIONATTRIBUTEASSEMBLYCONFIGURATIONATTRIBUTEASSEMBLYDESCRIPTIONATTRIBUTECOMPILATIONRELAXATIONSATTRIBUTEASSEMBLYPRODUCTATTRIBUTEASSEMBLYCOPYRIGHTATTRIBUTEASSEMBLYCOMPANYATTRIBUTERUNTIMECOMPATIBILITYATTRIBUTEQEMU-GA.EXESYSTEM.THREADINGSYSTEM.RUNTIME.VERSIONINGPROGRAMSYSTEMMAINSYSTEM.REFLECTIONSLEEP.CTORSYSTEM.DIAGNOSTICSSYSTEM.RUNTIME.INTEROPSERVICESSYSTEM.RUNTIME.COMPILERSERVICESDEBUGGINGMODESARGSOBJECT |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIG |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU WestVMware20,11696428655n |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe:Zone.IdentifieryD |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:/Users/user/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/qemu-ga.exe.configg |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: ms.portal.azure.comVMware20,11696428655 |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exeqemu-ga.exeows 10 Pro|C:\Windows|\Device\Harddisk0\Partition320240226161043.462189+060C:\Windows\Explorer.EXEC:\Windows\Explorer.EXEp3 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Windows\Temp\AslLog_shimengstate_qemu-ga.exe_7768.txt |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe0 |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407230924.0000000000D84000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe.0.dr | Binary or memory string: ProductNameqemu-ga4 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: global block list test formVMware20,11696428655 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Test URL for global passwords blocklistVMware20,11696428655 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.config |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: microsoft.visualstudio.comVMware20,11696428655x |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: AMC password management pageVMware20,11696428655 |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: tasks.office.comVMware20,11696428655o |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.comVMware20,11696428655 |
Source: driver.exe, 00000000.00000002.2426725873.0000000007292000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655 |
Source: driver.exe, 00000000.00000002.2412813228.0000000002671000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: \qemu-ga.exe |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe:Zone.Identifiery |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.00000000014B0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe" |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeGONS |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeY2 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.config |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: $cqYC:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}y |
Source: driver.exe, 00000000.00000002.2424787416.0000000006963000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeWinsta0\Default |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: bankofamerica.comVMware20,11696428655x |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/qemu-ga.exeigy7 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011D3000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemuP< |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe: |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exen@% |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407230924.0000000000D84000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe.0.dr | Binary or memory string: InternalNameqemu-ga.exeH |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Windows\assembly\NativeImages_v4.0.30319_64\qemu-ga\* |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.configz7 |
Source: qemu-ga.exe, 00000007.00000002.3451324423.0000000003061000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3451000317.0000000003211000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exe2 |
Source: driver.exe, 00000000.00000002.2424787416.0000000006963000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\Desktop\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe"C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe" |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: discord.comVMware20,11696428655f |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: s/Start Menu/Programs/Startup/qemu-ga.exe.configgUU9@P |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: turbotax.intuit.comVMware20,11696428655t |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: sers\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\qemu-h |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: dev.azure.comVMware20,11696428655j |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.comVMware20,11696428655} |
Source: qemu-ga.exe, 00000007.00000002.3451324423.0000000003061000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3451000317.0000000003211000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: `C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.config`_ |
Source: qemu-ga.exe, 00000007.00000002.3451324423.0000000003061000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3451000317.0000000003211000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: YC:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: secure.bankofamerica.comVMware20,11696428655|UE |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407230924.0000000000D84000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe.0.dr | Binary or memory string: FileDescriptionqemu-ga0 |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeeL |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office365.comVMware20,11696428655t |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU WestVMware20,11696428655n |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.configa7 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Windows\Temp\AslLog_ApphelpDebug_qemu-ga.exe_7768.txt P |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office.comVMware20,11696428655s |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655 |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.co.inVMware20,11696428655~ |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: ms.portal.azure.comVMware20,11696428655 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: discord.comVMware20,11696428655f |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exex7 |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407230924.0000000000D84000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe.0.dr | Binary or memory string: OriginalFilenameqemu-ga.exe0 |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: dev.azure.comVMware20,11696428655j |
Source: driver.exe, 00000000.00000002.2426725873.0000000007292000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe_ |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: netportal.hdfcbank.comVMware20,11696428655 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655^ |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: AMC password management pageVMware20,11696428655 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.comVMware20,11696428655 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.co.inVMware20,11696428655~ |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:UsersuserAppDataRoamingMicrosoftWindowsStart%20MenuProgramsStartupqemu-ga.exe.config! |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:a |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.00000000014B0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exC:P |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: trackpan.utiitsl.comVMware20,11696428655h |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - HKVMware20,11696428655] |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exeR( |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe.config |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.co.inVMware20,11696428655d |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - COM.HKVMware20,11696428655 |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe}2 |
Source: qemu-ga.exe, 00000007.00000002.3451324423.0000000003061000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3451000317.0000000003211000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exe.config |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: global block list test formVMware20,11696428655 |
Source: driver.exe, 00000000.00000002.2425509068.00000000071A5000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.00000000007EA000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420402313.0000000004D80000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.00000000007A5000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2426725873.0000000007283000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.000000000076E000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448198204.00000000010FA000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407186825.0000000000D82000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exe |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: `posoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: account.microsoft.com/profileVMware20,11696428655u |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\ya |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448198204.00000000010FA000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3450183788.00000000013A0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.00000000011D3000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448201010.000000000131A000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.00000000014B0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3450587378.00000000017A0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: secure.bankofamerica.comVMware20,11696428655|UE |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014E2000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\LocalC:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\qemu-ga.exe.log |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011D3000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exeT |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/qemu-ga.exe.config |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407186825.0000000000D82000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe, 00000007.00000002.3448639732.00000000011D3000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000002.3452196414.00007FF8482D4000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.00000000014E2000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3451978363.00007FF8482C4000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe.0.dr | Binary or memory string: qemu-ga |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\qemu-ga.exe.log |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exea7-C |
Source: driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: userAppDataRoamingMicrosoftWindowsStart%20MenuProgramsStartupqemu-ga.exe |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: turbotax.intuit.comVMware20,11696428655t |
Source: driver.exe, 00000000.00000002.2425509068.00000000071A5000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.00000000007EA000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420402313.0000000004D80000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2426725873.0000000007283000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2409925365.000000000076E000.00000004.00000020.00020000.00000000.sdmp, driver.exe, 00000000.00000002.2420596958.0000000004E0C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exeH |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: $cqYC:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe@\cq |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/qemu-ga.exee |
Source: driver.exe, 00000000.00000002.2425509068.00000000071A5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \Registry\Machine\Software\Classes\Applications\qemu-ga.exe |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeh |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - HKVMware20,11696428655] |
Source: driver.exe, 00000000.00000002.2410417036.0000000000821000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exee |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exef |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - COM.HKVMware20,11696428655 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.co.inVMware20,11696428655d |
Source: driver.exe, 00000000.00000002.2409029084.0000000000410000.00000004.00000020.00040000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe\??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeen-GBenen-USMyApplication.app |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011CE000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exen |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe0\Modules;C:\Program Files (x86)\AutoIt3\AutoItXPUBLIC=C:\Users\PublicSESSIONNAME=ConsoleSystemDrive=C:SystemRoot=C:\WindowsTEMP=C:\Users\user\AppData\Local\TempTa |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: netportal.hdfcbank.comVMware20,11696428655 |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exea |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Test URL for global passwords blocklistVMware20,11696428655 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeW |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655x |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga0 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655 |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exee |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: rtup\qemu-g |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655} |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office365.comVMware20,11696428655t |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:\Users\user\AppData\Roaming\Microsoft\Windows\Start%20Menu\Programs\Startup\qemu-ga.exeV |
Source: qemu-ga.exe, 00000009.00000002.3448924285.000000000151E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.configX7 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: account.microsoft.com/profileVMware20,11696428655u |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.configE |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655} |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655 |
Source: driver.exe, 00000000.00000002.2425509068.00000000071A5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \Registry\Machine\Software\Classes\Applications\qemu-ga.exeows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655^ |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe"C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe" C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeWinsta0\Defaultx7 |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exeqemu-ga.exe |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.comVMware20,11696428655} |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeC |
Source: driver.exe, 00000000.00000003.2378480001.0000000003C42000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: microsoft.visualstudio.comVMware20,11696428655x |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeD |
Source: driver.exe, 00000000.00000002.2420402313.0000000004D9B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655x |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office.comVMware20,11696428655s |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe8 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.000000000116C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe/ |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: tasks.office.comVMware20,11696428655o |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Windows\Temp\AslLog_ShimDebugLog_qemu-ga.exe_7768.txt l |
Source: driver.exe, 00000000.00000002.2412813228.000000000291A000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000007.00000000.2407186825.0000000000D82000.00000002.00000001.01000000.0000000E.sdmp, qemu-ga.exe.0.dr | Binary or memory string: <Module>qemu-gamscorlibThreadConsoleReadLineDebuggableAttributeComVisibleAttributeAssemblyTitleAttributeAssemblyTrademarkAttributeTargetFrameworkAttributeAssemblyFileVersionAttributeAssemblyConfigurationAttributeAssemblyDescriptionAttributeCompilationRelaxationsAttributeAssemblyProductAttributeAssemblyCopyrightAttributeAssemblyCompanyAttributeRuntimeCompatibilityAttributeqemu-ga.exeSystem.ThreadingSystem.Runtime.VersioningProgramSystemMainSystem.ReflectionSleep.ctorSystem.DiagnosticsSystem.Runtime.InteropServicesSystem.Runtime.CompilerServicesDebuggingModesargsObject |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe' |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655 |
Source: qemu-ga.exe, 00000007.00000002.3448639732.0000000001160000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\Desktop\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe"C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe" C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeWinsta0\Defaulte |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.configg |
Source: qemu-ga.exe, 00000009.00000002.3448924285.00000000014B8000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeRING=Internet ExplorerFPS_BROWSER_USER_PROFILE_STRING=DefaultHOMEDRIVE=C:HOMEPATH=\Users\userLOCALAPPDATA=C:\Users\user\AppData\LocalLOGONSERVER=\\user-PCNUMBER_OF_PROCESSORS=2OneDrive=C:\Users\user\OneDriveOS=Windows_NTPath=C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\WindowsG7 |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: trackpan.utiitsl.comVMware20,11696428655h |
Source: qemu-ga.exe, 00000007.00000002.3448639732.00000000011E4000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.configm |
Source: driver.exe, 00000000.00000003.2378480001.00000000039D9000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: bankofamerica.comVMware20,11696428655x |
Source: driver.exe, 00000000.00000002.2425574180.00000000071C6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe! |
Source: driver.exe, 00000000.00000002.2410370549.0000000000815000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe} |