Windows Analysis Report
5JPwmNu0eD.exe

Overview

General Information

Sample name: 5JPwmNu0eD.exe
renamed because original name is a hash value
Original sample name: c10ab9645fbf16b897e602b348c3479ce9abfe82a41f5e69fe0a6a196e691ef7.exe
Analysis ID: 1417306
MD5: b503c3727555bb1d97b96e58032f4f22
SHA1: b5fed92483584600ca9cf8f719c53d88a5db93f1
SHA256: c10ab9645fbf16b897e602b348c3479ce9abfe82a41f5e69fe0a6a196e691ef7
Infos:

Detection

Score: 84
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
Creates files in the recycle bin to hide itself
Drops PE files to the startup folder
Drops executables to the windows directory (C:\Windows) and starts them
Drops or copies MsMpEng.exe (Windows Defender, likely to bypass HIPS)
Machine Learning detection for sample
Creates files inside the system directory
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops PE files to the windows directory (C:\Windows)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Installs a raw input device (often for capturing keystrokes)
May sleep (evasive loops) to hinder dynamic analysis
Sample execution stops while process was sleeping (likely an evasion)
Stores files to the Windows start menu directory
Tries to load missing DLLs
Uses 32bit PE files

Classification

AV Detection

barindex
Source: 5JPwmNu0eD.exe Avira: detected
Source: C:\ProgramData\.curlrc.exe.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.exe.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\MF\Active.GRL.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Diagnosis\osver.txt.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\MF\Pending.GRL.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.exe.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.exe.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\Microsoft\Diagnosis\parse.dat.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\_curlrc.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\ProgramData\.curlrc.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.exe.tmp Avira: detection malicious, Label: TR/ATRAPS.Gen
Source: 5JPwmNu0eD.exe ReversingLabs: Detection: 95%
Source: 5JPwmNu0eD.exe Joe Sandbox ML: detected
Source: 5JPwmNu0eD.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: Binary string: d:\dbs\el\omr\target\x86\ship\click2run\x-none\Integrator.pdb source: integrator.exe.tmp.2.dr
Source: Binary string: d:\dbs\el\omr\target\x86\ship\click2run\x-none\Integrator.pdb0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: integrator.exe.tmp.2.dr
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\.curlrc.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\.curlrc.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\.curlrc.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\.curlrc.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\.curlrc.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\.curlrc.exe Jump to behavior
Source: integrator.exe.tmp.2.dr String found in binary or memory: http://127.0.0.1:13556/InsiderSlabBehaviorReportedBuildInsiderSlabBehaviorInsiderSlabBehaviorReporte
Source: integrator.exe.tmp.2.dr String found in binary or memory: https://nexus.officeapps.live.comhttps://nexusrules.officeapps.live.com
Source: integrator.exe.tmp.2.dr String found in binary or memory: https://otelrules.azureedge.net/rules/.bundlesdxhelper.exeFailed
Source: integrator.exe.tmp.2.dr Binary or memory string: RegisterRawInputDevices memstr_fa7589ce-c
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe File created: C:\Windows\SysWOW64\Zombie.exe Jump to behavior
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Section loaded: mfc42.dll Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe Section loaded: mfc42.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: mfc42.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Section loaded: wldp.dll Jump to behavior
Source: 5JPwmNu0eD.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: mal84.adwa.evad.winEXE@5/1393@0/0
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe File created: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\WER\Temp\965c09a6-ff8d-4ab0-8c44-dfc6cfd8416f.tmp Jump to behavior
Source: 5JPwmNu0eD.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\SysWOW64\Zombie.exe File read: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: integrator.exe.tmp.2.dr Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: integrator.exe.tmp.2.dr Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: integrator.exe.tmp.2.dr Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: integrator.exe.tmp.2.dr Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: 5JPwmNu0eD.exe ReversingLabs: Detection: 95%
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe File read: C:\Users\user\Desktop\5JPwmNu0eD.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\5JPwmNu0eD.exe "C:\Users\user\Desktop\5JPwmNu0eD.exe"
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Process created: C:\Windows\SysWOW64\Zombie.exe "C:\Windows\system32\Zombie.exe"
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Process created: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe "_ChocolateyInstall.ps1.exe"
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Process created: C:\Windows\SysWOW64\Zombie.exe "C:\Windows\system32\Zombie.exe" Jump to behavior
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Process created: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe "_ChocolateyInstall.ps1.exe" Jump to behavior
Source: Binary string: d:\dbs\el\omr\target\x86\ship\click2run\x-none\Integrator.pdb source: integrator.exe.tmp.2.dr
Source: Binary string: d:\dbs\el\omr\target\x86\ship\click2run\x-none\Integrator.pdb0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: integrator.exe.tmp.2.dr

Persistence and Installation Behavior

barindex
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Executable created and started: C:\Windows\SysWOW64\Zombie.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.lkg.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-AMFilter.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.lkg.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e64ffef1-e246-b632-595b-56076a3fa776.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ca-ES-valencia\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\DefenderPerformance.psd1.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\KeyHolder\61afd6a2-d7c3-8d25-36c2-0c2c47e3aca8.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Outlook.Outlook.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\71c8f37a-a7b9-aff0-6de0-9b276c089ad6.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ar-SA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ja-JP\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.E6.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpPerformanceReport.Format.ps1xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\06\89028913-695D-4F8F-BCE6-1E5C836C197B.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.67.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.dat.cat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-CA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdDevFlt.sys.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-BR\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.83.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\LfSvc\Geofence\GeofenceApplicationID.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fil-PH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\ecbc2601-0a67-4963-e594-43c65d6ec9a5.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpThreatDetection.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.Crwl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ProtectionManagement.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Lync.Lync.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fi-FI\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\15\FD83A2FA-E662-485E-9726-D8D117B311DE.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gu-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\.curlrc.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{31A74449-CB37-4ECC-AFE0-BB17DBA5F0AC}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pa-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\am-ET\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\Defender.psd1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe File created: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b34b197c-c0ed-bf12-c9bb-44e883c66a9d.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bcda97bb-bfd0-2a72-3c90-c8518f3d09ee.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b59f5123-f94a-28bc-cf2d-1f77c3cd60ad.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-MX\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{4C7ED29D-4CA0-4B8A-A1B0-8771A4123396}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-BR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3EDA3810-3491-4E83-A2AA-7EFB12171CF7}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpRollback.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\confident.cov.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.A0.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpThreat.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Microsoft-Antimalware-AMFilter.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\as-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fi-FI\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\nb-NO\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\ea39969e-9808-10a2-23ff-be783a132fea.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{F360F1F0-1516-4749-8FDA-56C0D526A6A0}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-CA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\nb-NO\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\he-IL\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\eee47229-947d-2ac7-e8a3-49bafee251d1.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231005-083136-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f1d940d0-b5b2-0083-8403-807a8db430d5.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Help File.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Microsoft-Windows-Windows Defender.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{62FC919B-273C-468F-973F-F41E1BBA604A}\mpuser.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpUpdate.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\02\837E475F-211F-4DAA-A7EF-B29AE54D6A99.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mt-MT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ca-ES-valencia\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.gthr.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ml-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1e77870d-1a93-60e5-ffda-9653c7cad20a.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ca-ES\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.man.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\eu-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe File created: C:\Windows\SysWOW64\Zombie.exe Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_settings.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fi-FI\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\bs-Latn-BA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.7C.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ProtectionManagement_Uninstall.mof.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.fbe50464-f61d-4a15-a5b7-ed239a079807.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.vdm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231005-082301-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.powerpointmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.hash.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-100619-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mk-MK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e8ac9388-7c9c-19cc-fd4d-cb72bb1544ea.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpPerformanceRecording.psm1.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\13edb933-4688-0f79-3d0a-499edf952ba0.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-CN\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.001.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.shared.Office.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\et-EE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpPerformanceRecording.wprp.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.f4d4c9b8-57b5-43ca-ab7a-5d857e7666b9.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mr-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\nl-NL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231004-092824-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8292682a-6850-c06c-9b6d-9646f16d4ed0.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\eu-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\as-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-085715-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Access.Access.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-095933-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lt-LT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-NIS.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\nn-NO\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\abbb44f6-ae33-2e7c-ac40-4d8ac17bf46b.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.809ce127-f5c0-40ef-bf85-cecccac2ef33.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-122008-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1659a225-428e-84f0-ba52-5fb2b85d55b3.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpWDOScan.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{17206FD8-D501-467A-8461-D4CD16DAE0D9}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\bs-Latn-BA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64ww.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpSvc.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Unknown.Log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cy-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e9bff135-4a26-0e2f-d743-30d9666eed8e.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ProtectionManagement_Uninstall.mof.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\52a7e8cc-4b89-0eb8-5b4c-0f924bfc3949.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpThreatCatalog.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bb26a0e5-d235-0ee6-0c36-6d5e185fa5b1.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\et-EE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.hash.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lo-LA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{12B0E5A4-D79A-45DF-838E-AC01484FC2C5}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.6C.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmmui.msi.16.en-us.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpPerformanceRecording.wprp.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\it-IT\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\154E23D0-C644-4E6F-8CE6-5069272F999F.vsch.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x64).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\c94a6c18-d496-da1c-8a02-fc6976e0145e.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\MasterDescriptor.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpUxAgent.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{62FC919B-273C-468F-973F-F41E1BBA604A}\mpavdlta.vdm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpThreatCatalog.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-122002-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mi-NZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpPerformanceReport.Format.ps1xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\01\9328EB67-F254-48BB-9DA6-3F76F41A0E9C.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\cb692946-a9f3-639d-1064-a6d75a01b9c3.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\com.microsoft.defender.be.firefox.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\endpointdlp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.Crwl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\9a9f1e94-851b-c6b4-27c0-55a242e0d96d.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ca-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fil-PH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b81d7e70-84e7-b16a-e3d0-1e7aa2f1232d.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\08\CC950129-487E-43A8-B5DC-2A23C6222934.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpComputerStatus.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-Protection.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Windows-Windows Defender.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{51F47079-4C5B-4BCE-8B60-6ABDED8A93F5}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\s320.hash.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\af-ZA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ar-SA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\436e78a7-dabb-5a30-f98d-963a03bf8af1.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lb-LU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ru-RU\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\3c8c7eb3-7a1d-7981-0472-571cdd1d1292.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Word.Word.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.vdm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Microsoft-Antimalware-Protection.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.fr-fr.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\am-ET\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_Office Feature Updates.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-GB\resource.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b6126597-8ecb-81b4-8b3a-1430dc2988c1.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hi-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lv-LV\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{21998843-E48C-4F95-BF9D-1FCCDB76BDF2}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCopyAccelerator.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{0BDE9245-0887-4D0E-AF72-3F842A887930}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.ba7c6d46-fc3a-452e-b58c-88c0a5384d76.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\i320.c2rx.hash.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.lyncmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-CA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.hash.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\fc93b452-8a84-dede-3b7a-0fc9413c4592.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\update-config.json.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\d834be1c-66d4-85d2-5bfc-720e73e8e544.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\WER\Temp\WERB4AB.tmp.WERInternalMetadata.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\quz-PE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-GB\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\UpdateLock-308046B0AF4A39CB.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\ac116a72-b6b1-d558-23f6-10796e634d41.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e2a686b1-b02a-b3e7-90cb-3fa0d708ce04.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\or-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Catalogs\IGD.CAT.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{27AA0E46-67D6-4248-876C-119B366B0CC4}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ro-RO\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\61b5bd89-4cb0-db77-6622-cb63b5a58080.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b34b197c-c0ed-bf12-c9bb-44e883c66a9d.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lv-LV\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-085557-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ca-ES\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\print_property.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpThreatDetection.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64\cab1.cab.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSMUX.OSMUX.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\21\7A3F9868-21FB-41DA-BAD8-070F118AB9C4.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\WER\Temp\965c09a6-ff8d-4ab0-8c44-dfc6cfd8416f.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ne-NP\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdBoot.sys.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-RTP.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.excelmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.onenotemui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\nl-NL\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.80.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-CA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\StableuserEtwLocation\mpuser_etw.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.07248d50-97f1-4932-b7a8-3060c262dd55.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.87.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\VirtualRegistry.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\bn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpEvMsg.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.01.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f1d940d0-b5b2-0083-8403-807a8db430d5.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\ca947da2-7e9a-7249-8095-bceb379c6f74.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\56598B41F139620898884E49C611C148.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\06\0ED1E367-1E22-4AFD-A208-D0061CB0CFDD.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.1d47542d-bdee-4dc6-94ed-be9cdb6f14e1.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For Updates.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\bg-BG\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.gthr.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpOAV.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\nl-NL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{62FC919B-273C-468F-973F-F41E1BBA604A}\mpasdlta.vdm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kok-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\id-ID\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6ab96728-2783-240f-370f-afa9d4e52fdd.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ga-IE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.d0cded3b-bc60-4eaa-b8ae-e2b969b977ba.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\bg-BG\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\nb-NO\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ka-GE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\c3d42a1a-2f3f-a4a9-6a04-cc1b234485fb.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.man.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For SQLite Updates.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\com.microsoft.defender.be.chrome.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_property.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.d9261b8a-d5e2-42ed-ab32-cd2fab1962fc.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\d1ecfce2-f845-c1e9-052b-d2f457c135e6.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\urgent.cov.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{37985AB5-E7D4-4674-920C-57A10432DE6D}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-GB\WelcomeFax.tif.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\MasterDescriptor.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e8fff2df-6041-8f21-3df7-db31661aa09b.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\3CCD5499-87A8-4B10-A215-608888DD3B55.vsch.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCommu.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpWDOScan.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ms-MY\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\81FE2459AB45799D6C1FB53DEEE30AF6.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-TW\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{53DDC43E-344A-49CD-ACDA-043ABC13F1FF}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_Office Feature Updates Logon.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e78cdb72-8076-1aa5-5df6-048300a0f594.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{298FA87E-B950-4D81-A5D8-7EC2DB6559B3}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3658DEA2-07B4-45D2-A78D-DA364921E14A}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\it-IT\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\c94a6c18-d496-da1c-8a02-fc6976e0145e.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\et-EE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ca-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\i320.c2rx.hash.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{599816D5-203B-4199-9494-22E61188AB58}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lt-LT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-114524-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\1A4B1382-EEB5-4D59-B0FA-B93F83A518E1-0.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpScan.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bbfbe8ad-1a35-a7f3-33bc-40912bf89dfb.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.a821f645-76e8-4ba9-965c-60ad931c30ce.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdNisDrv.sys.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\af-ZA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b59f5123-f94a-28bc-cf2d-1f77c3cd60ad.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDetours.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ro-RO\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bb26a0e5-d235-0ee6-0c36-6d5e185fa5b1.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.hash.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpPerformanceRecording.wprp.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-GB\resource.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\bg-BG\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-BR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-131119-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ProtectionManagement_Uninstall.mof.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\com.microsoft.defender.be.chrome.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pl-PL\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.DB.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\RtSigs\Data\b7851b46b4e32902708f1f5391c2e1bef58802ce.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64mui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\03f8974b-362e-33e3-2e0b-c7bc2ea01c63.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpSenseComm.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\generic.cov.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\com.microsoft.defender.be.firefox.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\DirectXDbVersion.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-125718-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-BR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\s321033.hash.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\operations.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\DefenderCSP.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x86).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Catalogs\IGD.CAT.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cy-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pl-PL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpSignature.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\07\6064F839-A1A6-488E-98E6-64026859F62C.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.publishermui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.e99a38d9-255f-44d4-9ce1-275e8cf23855.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8cfc804a-d777-2361-1670-4569e516397e.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-MX\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpPreference.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pl-PL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.gthr.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3251831E-957E-4C11-8C3F-80159E63BA37}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdFilter.sys.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-125143-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\ASAP_CloudPolicy.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\bn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}v14.36.32532\packages\vcRuntimeMinimum_amd64\cab1.cab.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Microsoft-Antimalware-Service.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.es-es.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gd-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-US\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{F15AA7CB-B4A2-4646-9E16-EFA5C568D9AF}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ProtectionManagement_Uninstall.mof.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fi-FI\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\.curlrc.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.7E.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8d56e57b-8663-136d-ff69-a004e217825a.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{483CFBC2-FDEC-448E-BE7B-F72AD070FECF}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\et-EE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\te-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.lkg.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-AMFilter.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.lkg.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{94DB5E4F-5EEE-4E34-8316-B18D9F37D7EF}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpClient.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\KeyHolder\61afd6a2-d7c3-8d25-36c2-0c2c47e3aca8.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231005-071726-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Cyrl-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\71c8f37a-a7b9-aff0-6de0-9b276c089ad6.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ja-JP\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\en-GB\mpasdesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win64.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-BR\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231005-082259-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpSenseComm.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win64.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\DesktopSettings2013.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6e90ed81-9187-fa62-ce90-f18d7bed6b12.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hu-HU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\15\FD83A2FA-E662-485E-9726-D8D117B311DE.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1faf63f7-f387-4522-1175-68c9652d968a.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Drivers\WdDevFlt.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpSignature.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\.curlrc.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{31A74449-CB37-4ECC-AFE0-BB17DBA5F0AC}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a7e08b8b-ad4b-af00-ebcc-1aa29a833ce9.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin64.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\Defender.psd1.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b34b197c-c0ed-bf12-c9bb-44e883c66a9d.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\52a7e8cc-4b89-0eb8-5b4c-0f924bfc3949.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpRollback.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{4C7ED29D-4CA0-4B8A-A1B0-8771A4123396}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3EDA3810-3491-4E83-A2AA-7EFB12171CF7}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\19\0.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpRollback.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1f7b7aa2-506a-03cd-6648-5b78ac12040f.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\154E23D0-C644-4E6F-8CE6-5069272F999F.vsch.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\865e8f30-20a1-9528-bb48-42999b5b2aa8.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f1d940d0-b5b2-0083-8403-807a8db430d5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{62FC919B-273C-468F-973F-F41E1BBA604A}\mpuser.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\02\837E475F-211F-4DAA-A7EF-B29AE54D6A99.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.gthr.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1e77870d-1a93-60e5-ffda-9653c7cad20a.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sk-SK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ug-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.man.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\215f9712-9fca-a3f8-5b11-660eefc73b96.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpPreference.cdxml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\User Account Pictures\hardz.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\config.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win64.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.fbe50464-f61d-4a15-a5b7-ed239a079807.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\CortanaUWP.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{C40F71FB-A0CD-46D7-A5AA-0E57C9BA9E1F}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpClient.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{BC4BE93B-34FF-4463-AA89-69BFD3D84502}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231005-082301-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\19\1.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0f8e2cd5-b8eb-7a22-b9e9-9b1183fa0a84.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mk-MK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e8ac9388-7c9c-19cc-fd4d-cb72bb1544ea.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Diagnosis\osver.txt.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00011.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-Eco3PTelDefault.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.f4d4c9b8-57b5-43ca-ab7a-5d857e7666b9.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Latn-RS\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.jfm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231004-092824-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pl-PL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-32.png.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Access.Access.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a1e5b165-0532-a6a3-f542-0c5c162be3e1.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-NIS.man.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ga-IE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\abbb44f6-ae33-2e7c-ac40-4d8ac17bf46b.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-122008-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1659a225-428e-84f0-ba52-5fb2b85d55b3.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{17206FD8-D501-467A-8461-D4CD16DAE0D9}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Unknown.Log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cy-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e9bff135-4a26-0e2f-d743-30d9666eed8e.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-PT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sr-Latn-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\User Account Pictures\guest.bmp.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bb26a0e5-d235-0ee6-0c36-6d5e185fa5b1.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\et-EE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\it-IT\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x64).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\vi-VN\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\th-TH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\c94a6c18-d496-da1c-8a02-fc6976e0145e.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpUxAgent.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-CN\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{7DE9C20C-810C-4780-AB50-C177DC64322C}.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.bk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpThreat.cdxml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\endpointdlp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8292682a-6850-c06c-9b6d-9646f16d4ed0.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.Crwl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fil-PH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin64.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Windows-Windows Defender.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\61b5bd89-4cb0-db77-6622-cb63b5a58080.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\af-ZA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpDetours.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\436e78a7-dabb-5a30-f98d-963a03bf8af1.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lb-LU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ru-RU\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\vi-VN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpScan.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\3c8c7eb3-7a1d-7981-0472-571cdd1d1292.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nb-NO\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ro-RO\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ru-RU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\C73297F3A28B41D0B045DECE1D0D81EF.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{E2C80A90-4D8C-4F08-A24C-F5E7848A4E51}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sk-SK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft OneDrive\setup\refcount.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.fr-fr.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_Office Feature Updates.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\AppV\Setup\OfficeIntegrator.ps1.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftWordpad.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b6126597-8ecb-81b4-8b3a-1430dc2988c1.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lv-LV\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{21998843-E48C-4F95-BF9D-1FCCDB76BDF2}.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{0BDE9245-0887-4D0E-AF72-3F842A887930}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpOAV.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\i320.c2rx.hash.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\fc93b452-8a84-dede-3b7a-0fc9413c4592.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.hash.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win64.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sr-Cyrl-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-40.png.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Office\ClickToRunPackageLocker.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Catalogs\IGD.CAT.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{27AA0E46-67D6-4248-876C-119B366B0CC4}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\MpDiag.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\61b5bd89-4cb0-db77-6622-cb63b5a58080.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\81FE2459AB45799D6C1FB53DEEE30AF6.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\VdiState.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpThreatDetection.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64\cab1.cab.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\uk-UA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edbtmp.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Unknown.Log.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdBoot.sys.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-RTP.man.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-GB\resource.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb00001.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\AppxProvisioning.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-CA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7309084a-bb6f-20c3-ea54-aa108ceab1ae.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.07248d50-97f1-4932-b7a8-3060c262dd55.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-TW\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.87.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{CD57D4D7-887A-494B-A386-6BEC95671675}.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00001.jrs.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\VirtualRegistry.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpEvMsg.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7646fa0f-b52c-71a8-3aed-950dd1668c09.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.01.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\th-TH\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\EaseOfAccessSettings2013.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\tr-TR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-BR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\uk-UA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For Updates.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.1d47542d-bdee-4dc6-94ed-be9cdb6f14e1.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ta-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\km-KH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.gthr.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sl-SI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8d56e57b-8663-136d-ff69-a004e217825a.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{62FC919B-273C-468F-973F-F41E1BBA604A}\mpasdlta.vdm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6ab96728-2783-240f-370f-afa9d4e52fdd.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ProtectionManagement.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.d0cded3b-bc60-4eaa-b8ae-e2b969b977ba.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ka-GE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Telemetry Log for Office.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For SQLite Updates.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\com.microsoft.defender.be.chrome.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edb.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_property.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\gu-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\2ff6ba33-4212-e6d3-dcc2-11aadb3d61ef.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pa-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{858A509E-DE26-4DF0-A1D9-851F87E9EE9D}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ThirdPartyNotices.txt.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpuserdb.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\81FE2459AB45799D6C1FB53DEEE30AF6.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Network\Downloader\edb00001.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ur-PK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{53DDC43E-344A-49CD-ACDA-043ABC13F1FF}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a92561ce-87c0-7d40-42ea-c87d237c0db0.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_Office Feature Updates Logon.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Diagnosis\parse.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e78cdb72-8076-1aa5-5df6-048300a0f594.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{298FA87E-B950-4D81-A5D8-7EC2DB6559B3}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3658DEA2-07B4-45D2-A78D-DA364921E14A}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-BR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ta-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x86).lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin32.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\13edb933-4688-0f79-3d0a-499edf952ba0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Latn-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ml-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\i320.c2rx.hash.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{599816D5-203B-4199-9494-22E61188AB58}.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpComputerStatus.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mt-MT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sl-SI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\1A4B1382-EEB5-4D59-B0FA-B93F83A518E1-0.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\Scripts\RegisterInboxTemplates.ps1.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpOAV.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpScan.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bbfbe8ad-1a35-a7f3-33bc-40912bf89dfb.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\USOShared\Logs\User\NotifyIcon.a821f645-76e8-4ba9-965c-60ad931c30ce.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdNisDrv.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231004-093351-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDetours.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ro-RO\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\vi-VN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.hash.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\9d3ad23c-c6b8-7fb5-e4ab-f5d0a66dcfbc.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\s320.hash.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231004-100144-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.DB.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64mui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\SciTE Script Editor.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-GB\generic.cov.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\com.microsoft.defender.be.firefox.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\CTAC.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ru-RU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jcp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\sync.ico.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb.chk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-125718-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2010.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\vi-VN\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\operations.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb00003.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ja-JP\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x86).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\2b5d0f60-d93b-1629-f3e5-4167231c7ee6.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\MF\Pending.GRL.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftNotepad.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\en-GB\mpasdesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpSignature.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin64.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sq-AL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6ab96728-2783-240f-370f-afa9d4e52fdd.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8cfc804a-d777-2361-1670-4569e516397e.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\VdiState.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbtmp.jtx.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8e383e90-b2f9-7bf2-1d5b-4e47dcb2014e.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pl-PL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{6CD35735-DB6C-4841-B376-FEBE51AD17BD}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.cert.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lt-LT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftNotepad.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3251831E-957E-4C11-8C3F-80159E63BA37}.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231004-093638-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\OneSettings\ASAP_CloudPolicy.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\com.microsoft.defender.be.firefox.json.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Package Cache\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}v14.36.32532\packages\vcRuntimeMinimum_amd64\cab1.cab.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.es-es.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-US\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\Templates\SettingsLocationTemplate2013A.xsd.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{F15AA7CB-B4A2-4646-9E16-EFA5C568D9AF}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\.curlrc.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.7E.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lo-LA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ru-RU\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\it-IT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\User Account Pictures\user-48.png.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-PT\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e64ffef1-e246-b632-595b-56076a3fa776.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ca-ES-valencia\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\DefenderPerformance.psd1.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Outlook.Outlook.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\User Account Pictures\defaultuser0.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe File created: C:\Windows\SysWOW64\Zombie.exe Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\desktop.ini.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Access.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\desktop.ini.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Excel.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Firefox.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\OneNote.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Outlook.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Word.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\7-Zip\7-Zip Help.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Access.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\desktop.ini.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Notepad.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Paint.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Quick Assist.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Wordpad.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Adobe Acrobat.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\desktop.ini.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Excel.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Firefox Private Browsing.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Firefox.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Google Chrome.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\About Java.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Check For Updates.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Get Help.url.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Visit Java.com.url.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Maintenance\Desktop.ini.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Edge.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\OneNote.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Outlook.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\PowerPoint.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Publisher.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Skype for Business.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessibility\Speech Recognition.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Math Input Panel.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Steps Recorder.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\System Tools\desktop.ini.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Windows Media Player.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Component Services.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Computer Management.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\desktop.ini.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\dfrgui.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Event Viewer.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Print Management.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Registry Editor.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\System Configuration.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\System Information.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\AutoIt Help File.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x86).lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Check For SQLite Updates.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Check For Updates.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x64).lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x86).lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Firefox Private Browsing.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\desktop.ini.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Component Services.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Computer Management.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\desktop.ini.exe.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Word.lnk.exe.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessibility\desktop.ini.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\Snipping Tool.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Examples.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Configure Java.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\StartUp\desktop.ini.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\desktop.ini.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\System Tools\Task Manager.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Computer Management.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Extras\Browse Extras.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Run Script (x64).lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\Run Script (x86).lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\AutoIt v3\SciTE Script Editor.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\desktop.ini.exe.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Skype for Business Recording Manager.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Telemetry Log for Office.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk.tmp Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\SysWOW64\Zombie.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Jump to behavior
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\5JPwmNu0eD.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe Window / User API: threadDelayed 2964 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe Window / User API: threadDelayed 1902 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe Window / User API: threadDelayed 676 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Window / User API: threadDelayed 712 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Window / User API: threadDelayed 2100 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Window / User API: threadDelayed 2844 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\folder.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\IdentityCRL\INT\wlidsvcconfig.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\ProtectionManagement.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\te-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\3CCD5499-87A8-4B10-A215-608888DD3B55.vsch.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.lkg.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-AMFilter.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpasdlta.lkg.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.lkg.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{94DB5E4F-5EEE-4E34-8316-B18D9F37D7EF}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win32.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpClient.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\KeyHolder\61afd6a2-d7c3-8d25-36c2-0c2c47e3aca8.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Microsoft-Windows-Windows Defender.man.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user.png.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\NetworkPrinters.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231005-071726-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\Apps\28502d06-9d29-8514-1e5d-64447116d798.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Cyrl-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpClient.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpEvMsg.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\71c8f37a-a7b9-aff0-6de0-9b276c089ad6.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ja-JP\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\edb00011.jtx.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\en-GB\mpasdesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win64.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-BR\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231005-082259-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpClient.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpSenseComm.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win64.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Desktop\Google Chrome.lnk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\DesktopSettings2013.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6e90ed81-9187-fa62-ce90-f18d7bed6b12.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hu-HU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office64mui.msi.16.en-us.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1faf63f7-f387-4522-1175-68c9652d968a.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\15\FD83A2FA-E662-485E-9726-D8D117B311DE.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Drivers\WdDevFlt.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpSignature.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\.curlrc.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{31A74449-CB37-4ECC-AFE0-BB17DBA5F0AC}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a7e08b8b-ad4b-af00-ebcc-1aa29a833ce9.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpDetoursCopyAccelerator.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin32.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpAsDesc.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin64.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Network\Downloader\edb.chk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fi-FI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\et-EE\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\Defender.psd1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpUpdate.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b34b197c-c0ed-bf12-c9bb-44e883c66a9d.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Store\56598B41F139620898884E49C611C148.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\52a7e8cc-4b89-0eb8-5b4c-0f924bfc3949.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpRollback.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{4C7ED29D-4CA0-4B8A-A1B0-8771A4123396}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\User\NotifyIcon.d0cded3b-bc60-4eaa-b8ae-e2b969b977ba.1.etl.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3EDA3810-3491-4E83-A2AA-7EFB12171CF7}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\19\0.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpRollback.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1f7b7aa2-506a-03cd-6648-5b78ac12040f.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Package Cache\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}v14.36.32532\packages\vcRuntimeMinimum_amd64\cab1.cab.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\154E23D0-C644-4E6F-8CE6-5069272F999F.vsch.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\865e8f30-20a1-9528-bb48-42999b5b2aa8.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\f1d940d0-b5b2-0083-8403-807a8db430d5.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\osver.txt.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\TroubleshootingSvc.json.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{62FC919B-273C-468F-973F-F41E1BBA604A}\mpuser.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\02\837E475F-211F-4DAA-A7EF-B29AE54D6A99.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\wordEtw.man.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpDetours.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.1.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.gthr.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents\My Videos\desktop.ini.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\am-ET\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win64.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\{62FC919B-273C-468F-973F-F41E1BBA604A}\mpavdlta.vdm.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1e77870d-1a93-60e5-ffda-9653c7cad20a.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MsMpLics.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Outlook.lnk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-PT\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sk-SK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpAsDesc.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ug-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.man.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\215f9712-9fca-a3f8-5b11-660eefc73b96.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin64.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin64.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\21\7A3F9868-21FB-41DA-BAD8-070F118AB9C4.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpPreference.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sv-SE\MpEvMsg.dll.mui.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\config.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\hardz.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win64.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016Win32.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.fbe50464-f61d-4a15-a5b7-ed239a079807.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\CortanaUWP.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin64.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\User\NotifyIcon.e99a38d9-255f-44d4-9ce1-275e8cf23855.1.etl.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{C40F71FB-A0CD-46D7-A5AA-0E57C9BA9E1F}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpThreatCatalog.cdxml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpClient.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{BC4BE93B-34FF-4463-AA89-69BFD3D84502}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\MpEvMsg.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nl-NL\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\Apps\b59f5123-f94a-28bc-cf2d-1f77c3cd60ad.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftNotepad.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231005-082301-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Users\Public\Pictures\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\ReportLatency\Latency\19\1.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-ES\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\0f8e2cd5-b8eb-7a22-b9e9-9b1183fa0a84.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mk-MK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Registry Editor.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e8ac9388-7c9c-19cc-fd4d-cb72bb1544ea.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\AutoIt Window Info (x64).lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\osver.txt.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Word.lnk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\te-IN\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00011.jtx.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Results\Resource\{53DDC43E-344A-49CD-ACDA-043ABC13F1FF}.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.P-Eco3PTelDefault.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\DeploymentConfig.1.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory\01\9328EB67-F254-48BB-9DA6-3F76F41A0E9C.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sr-Latn-RS\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.f4d4c9b8-57b5-43ca-ab7a-5d857e7666b9.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Results\Resource\{298FA87E-B950-4D81-A5D8-7EC2DB6559B3}.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents\My Pictures\desktop.ini.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftLync2010.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Support\MpWppTracing-20231005-083136-00000003-ffffffff.bin.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kn-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.jfm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231004-092824-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Users\Public\Desktop\Google Chrome.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\Apps\1659a225-428e-84f0-ba52-5fb2b85d55b3.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pl-PL\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\Apps\8292682a-6850-c06c-9b6d-9646f16d4ed0.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user-32.png.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Access.Access.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\it-IT\MpEvMsg.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\a1e5b165-0532-a6a3-f542-0c5c162be3e1.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\desktop.ini.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ga-IE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-NIS.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\abbb44f6-ae33-2e7c-ac40-4d8ac17bf46b.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Support\MpWppTracing-20231003-122008-00000003-ffffffff.bin.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\1659a225-428e-84f0-ba52-5fb2b85d55b3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sq-AL\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\netfol.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\update-config.json.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{17206FD8-D501-467A-8461-D4CD16DAE0D9}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Word.Word.x-none.msi.16.x-none.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cy-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\e9bff135-4a26-0e2f-d743-30d9666eed8e.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-PT\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sr-Latn-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ja-JP\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Support\MPDetection-20231003-085557.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\guest.bmp.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ar-SA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpRtp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\bb26a0e5-d235-0ee6-0c36-6d5e185fa5b1.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\User\NotifyIcon.d9261b8a-d5e2-42ed-ab32-cd2fab1962fc.1.etl.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-BR\ProtectionManagement.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\et-EE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\it-IT\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Compile Script to .exe (x64).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\vi-VN\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\th-TH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\c94a6c18-d496-da1c-8a02-fc6976e0145e.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-BR\MpEvMsg.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\state.rsm.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\DefenderPerformance.psd1.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpUxAgent.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\en-US\MpAsDesc.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpAzSubmit.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\Apps\52a7e8cc-4b89-0eb8-5b4c-0f924bfc3949.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\IdentityCRL\production\wlidsvcconfig.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-CN\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\User\NotifyIcon.a821f645-76e8-4ba9-965c-60ad931c30ce.1.etl.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\en-GB\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{7DE9C20C-810C-4780-AB50-C177DC64322C}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pa-IN\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.bk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.hash.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpRtp.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Results\Resource\{94DB5E4F-5EEE-4E34-8316-B18D9F37D7EF}.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.dat.cat.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpThreat.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\lv-LV\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\gl-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoItX\AutoItX Help File.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sq-AL\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\bg-BG\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8292682a-6850-c06c-9b6d-9646f16d4ed0.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\endpointdlp.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.Crwl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\fil-PH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpavdlta.vdm.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\de-DE\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin64.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\MpAsDesc.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Windows-Windows Defender.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hr-HR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\61b5bd89-4cb0-db77-6622-cb63b5a58080.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\ScenariosSqlStore\EventStore.db.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\af-ZA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpDetours.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Extras\AutoIt v3 Website.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\436e78a7-dabb-5a30-f98d-963a03bf8af1.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lb-LU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Private Browsing.lnk.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ru-RU\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\vi-VN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\DeviceMetadataCache\dmrc.idx.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpScan.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpDetoursCopyAccelerator.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\3c8c7eb3-7a1d-7981-0472-571cdd1d1292.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\nb-NO\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Users\Public\Videos\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ro-RO\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ru-RU\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Users\Public\Desktop\Firefox.lnk.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\C73297F3A28B41D0B045DECE1D0D81EF.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{E2C80A90-4D8C-4F08-A24C-F5E7848A4E51}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\sk-SK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft OneDrive\setup\refcount.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.fr-fr.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mr-IN\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_Office Feature Updates.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\AppV\Setup\OfficeIntegrator.ps1.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftWordpad.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\ProtectionManagement.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\az-Latn-AZ\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\b6126597-8ecb-81b4-8b3a-1430dc2988c1.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\lv-LV\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{21998843-E48C-4F95-BF9D-1FCCDB76BDF2}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{0BDE9245-0887-4D0E-AF72-3F842A887930}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\DeploymentConfig.2.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Excel.lnk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\de-DE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Store\81FE2459AB45799D6C1FB53DEEE30AF6.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016Win64.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\Apps\13edb933-4688-0f79-3d0a-499edf952ba0.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpOAV.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\i320.c2rx.hash.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Network\Downloader\edbres00002.jrs.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpPerformanceRecording.wprp.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\fc93b452-8a84-dede-3b7a-0fc9413c4592.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\stream.x86.x-none.hash.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win64.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.fr-fr.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Documents\My Videos\desktop.ini.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\OneSettings\TroubleshootingSvc.json.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sr-Cyrl-RS\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ms-MY\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\User Account Pictures\user-40.png.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\ClipSVC\Archive\Apps\61b5bd89-4cb0-db77-6622-cb63b5a58080.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Office\ClickToRunPackageLocker.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpUxAgent.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Catalogs\IGD.CAT.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{27AA0E46-67D6-4248-876C-119B366B0CC4}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\MpDiag.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\cs-CZ\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\zh-TW\ProtectionManagement.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\61b5bd89-4cb0-db77-6622-cb63b5a58080.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\81FE2459AB45799D6C1FB53DEEE30AF6.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\az-Latn-AZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\VdiState.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-FR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Service\History.Log.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Powershell\MSFT_MpThreatDetection.cdxml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64\cab1.cab.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\uk-UA\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-CN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edbtmp.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\pt-PT\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-GB\resource.xml.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Microsoft-Antimalware-RTP.man.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\Drivers\WdBoot.sys.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb00001.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fa-IR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\AppxProvisioning.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7309084a-bb6f-20c3-ea54-aa108ceab1ae.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\fr-CA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.07248d50-97f1-4932-b7a8-3060c262dd55.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\zh-TW\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{CD57D4D7-887A-494B-A386-6BEC95671675}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.87.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edbres00001.jrs.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\VirtualRegistry.dat.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpEvMsg.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\7646fa0f-b52c-71a8-3aed-950dd1668c09.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Support\MpWppTracing-20231003-100619-00000003-ffffffff.bin.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.01.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\th-TH\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ca-ES-valencia\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\endpointdlp.dll.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\EaseOfAccessSettings2013.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\tr-TR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin32.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pt-BR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpLics.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\el-GR\MpAsDesc.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\uk-UA\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For Updates.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.1d47542d-bdee-4dc6-94ed-be9cdb6f14e1.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\InboxTemplates\VdiState.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.2.gthr.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\cs-CZ\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.lyncmui.msi.16.en-us.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ta-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\km-KH\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Scans\History\Results\Resource\{B4E0C99D-A1B5-451C-8C4D-2FC579C5B5A2}.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.3.gthr.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ko-KR\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\en-us.16\stream.x86.en-us.hash.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Detections.log.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\sl-SI\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\8d56e57b-8663-136d-ff69-a004e217825a.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\ClickToRun\ProductReleases\39D4F9E5-695B-46C1-A26C-5CA55C23376D\x-none.16\s320.hash.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\UEV\Templates\SettingsLocationTemplate.xsd.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{62FC919B-273C-468F-973F-F41E1BBA604A}\mpasdlta.vdm.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\6ab96728-2783-240f-370f-afa9d4e52fdd.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\ringtones.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ProtectionManagement.dll.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\es-ES\MpEvMsg.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\USOShared\Logs\User\NotifyIcon.d0cded3b-bc60-4eaa-b8ae-e2b969b977ba.1.etl.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Microsoft-Antimalware-NIS.man.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ka-GE\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Telemetry Log for Office.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Accessories\System Tools\Character Map.lnk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3\Check For SQLite Updates.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-GB\resource.xml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\com.microsoft.defender.be.chrome.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\com.microsoft.defender.be.firefox.json.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\en-US\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.tracing.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ko-KR\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Network\Downloader\edb.log.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\hu-HU\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\kk-KZ\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\scan_property.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Desktop\Firefox.lnk.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5F2FFB7A31DBA078D8F948F77F0FE9B82BEB1559.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\gu-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\da-DK\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\ClipSVC\Archive\Apps\2ff6ba33-4212-e6d3-dcc2-11aadb3d61ef.xml.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\Powershell\MSFT_MpRollback.cdxml.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\pa-IN\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\OneSettings\StorageGroveler.json.exe.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\folder.ico.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\TELEMETRY.ASM-WINDOWSSQ.json.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{858A509E-DE26-4DF0-A1D9-851F87E9EE9D}.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ThirdPartyNotices.txt.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\es-MX\mpuxagent.dll.mui.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ar-SA\mpuxagent.dll.mui.exe (copy) Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe Dropped PE file which has not been started: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\OneSettings\ASAP_CloudPolicy.json.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\hr-HR\MpAsDesc.dll.mui.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Scans\mpuserdb.db.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\Zombie.exe TID: 6084 Thread sleep count: 2964 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe TID: 6084 Thread sleep count: 1902 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe TID: 6084 Thread sleep count: 676 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe TID: 6084 Thread sleep count: 265 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe TID: 6084 Thread sleep count: 265 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe TID: 6084 Thread sleep count: 53 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe TID: 6084 Thread sleep count: 37 > 30 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe TID: 6032 Thread sleep count: 712 > 30 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe TID: 6032 Thread sleep count: 295 > 30 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe TID: 6032 Thread sleep count: 2100 > 30 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe TID: 6032 Thread sleep count: 2844 > 30 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe TID: 6032 Thread sleep count: 282 > 30 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe TID: 6032 Thread sleep count: 52 > 30 Jump to behavior
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe TID: 6032 Thread sleep count: 36 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\Zombie.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\.curlrc.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\.curlrc.exe.tmp Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\.curlrc.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\.curlrc.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\.curlrc.exe Jump to behavior
Source: C:\Windows\SysWOW64\Zombie.exe File opened: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\.curlrc.exe Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\_ChocolateyInstall.ps1.exe File created: C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe (copy) Jump to dropped file
No contacted IP infos