Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: <pi-ms-win-core-localization-l1-2-1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: dxgidebug.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: iconcodecservice.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: pcacli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: windows.fileexplorer.common.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: ntshrui.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\H9gMIu2HXi.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: <pi-ms-win-core-localization-l1-2-1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: dxgidebug.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: pcacli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: windows.fileexplorer.common.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: ntshrui.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX0\work.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: <pi-ms-win-core-synch-l1-2-0.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: <pi-ms-win-core-fibers-l1-1-1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: <pi-ms-win-core-localization-l1-2-1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: dxgidebug.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: policymanager.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: msvcp110_win.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: pcacli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\RarSFX1\dwartg.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: dlnashext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: wpdshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ktmw32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: dlnashext.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: wpdshext.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
Section loaded: version.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
Section loaded: mscoree.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: mscoree.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: apphelp.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: version.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: wldp.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: profapi.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: sspicli.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: mscoree.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: version.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: wldp.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: profapi.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Program Files (x86)\MSBuild\Microsoft\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: taskschd.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\schtasks.exe |
Section loaded: xmllite.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: sspicli.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: mscoree.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: apphelp.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: version.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: wldp.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: profapi.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: sspicli.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: mscoree.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: version.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: wldp.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: profapi.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
|
Source: C:\Windows\System32\chcp.com |
Section loaded: ulib.dll |
|
Source: C:\Windows\System32\chcp.com |
Section loaded: fsutilext.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: logoncli.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: ntdsapi.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: fwpuclnt.dll |
|
Source: C:\Windows\System32\w32tm.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: mscoree.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\AppData\Roaming\msBroker\SurrogatewebSession.exe |
Section loaded: sspicli.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: mscoree.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: apphelp.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: version.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: wldp.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: profapi.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Program Files\Windows Multimedia Platform\vXKtedDiKZHKptbUFqIBdHmZ.exe |
Section loaded: sspicli.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: mscoree.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: version.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: wldp.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: profapi.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: sspicli.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: ktmw32.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: propsys.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: edputil.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: urlmon.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: iertutil.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: srvcli.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: netutils.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: wintypes.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: appresolver.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: bcp47langs.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: slc.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: userenv.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: sppc.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: onecorecommonproxystub.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: mpr.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: pcacli.dll |
|
Source: C:\Recovery\winlogon.exe |
Section loaded: sfc_os.dll |
|