Source: |
Binary string: Qatvhs.pdb source: SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.0000000004110000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1490428005.0000000005520000.00000004.08000000.00040000.00000000.sdmp, Keywords.exe, 00000007.00000002.1635965900.00000000046DE000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000015.00000002.2866397789.000000000473E000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1447665099.000000000459A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1443307685.00000000031DC000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1461796579.0000000005F90000.00000004.08000000.00040000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.0000000004497000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.0000000004555000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1470593707.0000000003038000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000005.00000002.1530270940.0000000002AFD000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000007.00000002.1635965900.00000000048B3000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000007.00000002.1588820194.00000000034A1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000008.00000002.1685032824.0000000003931000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000008.00000002.1685032824.0000000003981000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000008.00000002.1635084673.0000000002C44000.00000004.00000800.00020000.00000000.sdmp, fdyryi.exe, 0000000F.00000002.1746723723.0000029A0036B000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000011.00000002.1872584736.0000000002F88000.00000004.00000800.00020000.00000000.sdmp, AlgorithmType.exe, 00000014.00000002.1910595763.000001B806521000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000017.00000002.1968077949.00000154E5C11000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000017.00000002.2317223461.00000154F5DF2000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000017.00000002.2317223461.00000154F5DF4000.00000004.00000800.00020000.00000000.sdmp, pjmskbbdr.exe, 0000001B.00000002.2248679548.000000000342E000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1447665099.000000000459A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1443307685.00000000031DC000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1461796579.0000000005F90000.00000004.08000000.00040000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.0000000004497000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.0000000004555000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1470593707.0000000003038000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000005.00000002.1530270940.0000000002AFD000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000007.00000002.1635965900.00000000048B3000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000007.00000002.1588820194.00000000034A1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000008.00000002.1685032824.0000000003931000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000008.00000002.1685032824.0000000003981000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000008.00000002.1635084673.0000000002C44000.00000004.00000800.00020000.00000000.sdmp, fdyryi.exe, 0000000F.00000002.1746723723.0000029A0036B000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000011.00000002.1872584736.0000000002F88000.00000004.00000800.00020000.00000000.sdmp, AlgorithmType.exe, 00000014.00000002.1910595763.000001B806521000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000017.00000002.1968077949.00000154E5C11000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000017.00000002.2317223461.00000154F5DF2000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000017.00000002.2317223461.00000154F5DF4000.00000004.00000800.00020000.00000000.sdmp, pjmskbbdr.exe, 0000001B.00000002.2248679548.000000000342E000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: protobuf-net.pdbSHA256}Lq source: SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1461192975.0000000005EE0000.00000004.08000000.00040000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1443307685.0000000003123000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.0000000004497000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000005.00000002.1530270940.0000000002C98000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000008.00000002.1635084673.0000000002B8B000.00000004.00000800.00020000.00000000.sdmp, fdyryi.exe, 00000010.00000002.2305476496.000001A956CF2000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000011.00000002.1872584736.0000000002E0B000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000011.00000002.2144258743.0000000003BB1000.00000004.00000800.00020000.00000000.sdmp, AlgorithmType.exe, 00000014.00000002.2143085214.000001B81637E000.00000004.00000800.00020000.00000000.sdmp, AlgorithmType.exe, 00000016.00000002.2526240071.0000020541BF7000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000017.00000002.2317223461.00000154F5B27000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: Zjcufvpnldc.pdb source: fdyryi.exe, 00000010.00000002.2305476496.000001A95698A000.00000004.00000800.00020000.00000000.sdmp, fdyryi.exe, 00000010.00000002.2305476496.000001A956A92000.00000004.00000800.00020000.00000000.sdmp, AlgorithmType.exe, 00000016.00000002.1915461122.00000205312B0000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: protobuf-net.pdb source: SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1461192975.0000000005EE0000.00000004.08000000.00040000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000002.1443307685.0000000003123000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.0000000004497000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000002.00000002.1480296613.00000000042EC000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000005.00000002.1530270940.0000000002C98000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000008.00000002.1635084673.0000000002B8B000.00000004.00000800.00020000.00000000.sdmp, fdyryi.exe, 00000010.00000002.2305476496.000001A956CF2000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000011.00000002.1872584736.0000000002E0B000.00000004.00000800.00020000.00000000.sdmp, Keywords.exe, 00000011.00000002.2144258743.0000000003BB1000.00000004.00000800.00020000.00000000.sdmp, AlgorithmType.exe, 00000014.00000002.2143085214.000001B81637E000.00000004.00000800.00020000.00000000.sdmp, AlgorithmType.exe, 00000016.00000002.2526240071.0000020541BF7000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000017.00000002.2317223461.00000154F5B27000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: .pdb source: SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe, 00000000.00000000.1391740961.00000000009D2000.00000002.00000001.01000000.00000003.sdmp, Keywords.exe, 00000007.00000002.1635965900.00000000048B3000.00000004.00000800.00020000.00000000.sdmp |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Elevation |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoader46.57007.12424.22631.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Elevation |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Local\jautwk\Keywords.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Elevation |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Elevation |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Local\Temp\fdyryi.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32 |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Elevation |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD} |
|
Source: C:\Users\user\AppData\Roaming\NamedPermissionSets\AlgorithmType.exe |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs |
|