Windows Analysis Report
GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe

Overview

General Information

Sample name: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
Analysis ID: 1430937
MD5: fd2c102f6b2dac90179d7981dc7299e1
SHA1: 36b30f7173dae7c450e24204cd432b122121ebb3
SHA256: 4627b4f84258eede9176028143c17f0ef56d649b4ff4ba4d218a2609bf0193f5
Infos:

Detection

Score: 27
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Compliance

Score: 19
Range: 0 - 100

Signatures

Installs a global event hook (focus changed)
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
DLL planting / hijacking vulnerabilities found
Drops PE files
EXE planting / hijacking vulnerabilities found
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sigma detected: CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: MSVCP140_CLR0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: LINKINFO.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: ncrypt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: WINMM.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PowerPointApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Memory.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.CheetahClient.Protocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.batteries_v2.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\TestableIO.System.IO.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Threading.Tasks.Extensions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.UI.Onboarding.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.provider.dynamic_cdecl.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.StorageClient.Protocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Encodings.Web.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: d3d10warp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Serialization.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Resources.Extensions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.core.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: RichEd20.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NLog.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: Wldp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\TestableIO.System.IO.Abstractions.Wrappers.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: D3DCOMPILER_47.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Wpf.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Core.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: USERENV.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Buffers.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Linq.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: msvcp110_win.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Toolkit.Uwp.Notifications.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\OfficeApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: d3d9.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\VBIDEApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.UIAutomation.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.SHCore.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: msls31.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: USP10.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Data.Sqlite.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm64\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: WinTypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.WinForms.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Interfaces.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: CRYPTSP.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Bcl.AsyncInterfaces.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.IAccessible2Lib.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\stdole.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Xaml.Behaviors.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: BROWCLI.Dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: CRYPTBASE.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Kernel32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.User32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\websocket-sharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Collections.Immutable.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\WordApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Validation.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: profapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.AdvApi32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Numerics.Vectors.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LZStringCSharp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: cscapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: edputil.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.ShellSuserngApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: twinapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Runtime.CompilerServices.Unsafe.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NetOffice.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.ValueTuple.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Newtonsoft.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.IO.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe EXE: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe EXE: tasklist.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe EXE: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Uninstall.exe

Compliance

barindex
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: MSVCP140_CLR0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: LINKINFO.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: ncrypt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: WINMM.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PowerPointApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Memory.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.CheetahClient.Protocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.batteries_v2.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\TestableIO.System.IO.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Threading.Tasks.Extensions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.UI.Onboarding.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.provider.dynamic_cdecl.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.StorageClient.Protocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Encodings.Web.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: d3d10warp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Serialization.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Resources.Extensions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.core.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: RichEd20.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NLog.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: Wldp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\TestableIO.System.IO.Abstractions.Wrappers.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: D3DCOMPILER_47.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Wpf.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Core.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: USERENV.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Buffers.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Linq.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: msvcp110_win.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Toolkit.Uwp.Notifications.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\OfficeApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: d3d9.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\VBIDEApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.UIAutomation.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.SHCore.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: msls31.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: USP10.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Data.Sqlite.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm64\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: WinTypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.WinForms.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Interfaces.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: CRYPTSP.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Bcl.AsyncInterfaces.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.IAccessible2Lib.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\stdole.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Xaml.Behaviors.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: BROWCLI.Dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: CRYPTBASE.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Kernel32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.User32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\websocket-sharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Collections.Immutable.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\WordApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Validation.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: profapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.AdvApi32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Numerics.Vectors.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LZStringCSharp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: cscapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: edputil.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.ShellSuserngApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe DLL: twinapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Runtime.CompilerServices.Unsafe.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NetOffice.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.ValueTuple.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Newtonsoft.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe DLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.IO.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe EXE: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe EXE: tasklist.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe EXE: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Uninstall.exe
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Grammarly Desktop Integrations
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-DiffMatchPatch.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NHotkey.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NLog.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NewtonsoftJson.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-Validation.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-dotnet.txt
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Static PE information: certificate valid
Source: unknown HTTPS traffic detected: 34.197.163.13:443 -> 192.168.2.16:49728 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.231.17.194:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.231.17.194:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.21.223.151:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknown HTTPS traffic detected: 18.208.47.8:443 -> 192.168.2.16:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 107.22.173.72:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.197.163.13:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 44.205.78.241:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.211.23.45:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.73.100.250:443 -> 192.168.2.16:50127 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.235.239.81:443 -> 192.168.2.16:50175 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.235.239.81:443 -> 192.168.2.16:50184 version: TLS 1.2
Source: unknown HTTPS traffic detected: 18.154.132.81:443 -> 192.168.2.16:50198 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.235.76.136:443 -> 192.168.2.16:50200 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.3.124.253:443 -> 192.168.2.16:50201 version: TLS 1.2
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData\Local
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData\Local\Grammarly
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown TCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknown DNS traffic detected: queries for: win-extension.femetrics.grammarly.io
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49986
Source: unknown Network traffic detected: HTTP traffic on port 49817 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49985
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49984
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49983
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49982
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49981
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49980
Source: unknown Network traffic detected: HTTP traffic on port 49932 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49898 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49852 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50131 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50211 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 50177 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49979
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49978
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49977
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49976
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49975
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49974
Source: unknown Network traffic detected: HTTP traffic on port 50085 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49973
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49972
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49971
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49970
Source: unknown Network traffic detected: HTTP traffic on port 50165 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50004 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49909 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49969
Source: unknown Network traffic detected: HTTP traffic on port 49978 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49886 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49968
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49967
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49966
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49965
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49964
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49963
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49962
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49961
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49960
Source: unknown Network traffic detected: HTTP traffic on port 49966 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50189 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50108 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50073 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49805 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49959
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49958
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49957
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49956
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49955
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49954
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49953
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49952
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49951
Source: unknown Network traffic detected: HTTP traffic on port 49839 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49864 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49950
Source: unknown Network traffic detected: HTTP traffic on port 49944 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49910 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50051 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49796 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50153 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49949
Source: unknown Network traffic detected: HTTP traffic on port 50235 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49948
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49947
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49946
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49945
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49944
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49701
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49943
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49787
Source: unknown Network traffic detected: HTTP traffic on port 50061 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49786
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49785
Source: unknown Network traffic detected: HTTP traffic on port 49922 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49784
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49783
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 49968 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50187 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50221 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 49862 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 50095 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49830 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50155 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49991 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 50038 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 50143 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49840 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50208 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49896 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49956 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 50083 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49999
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49998
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49997
Source: unknown Network traffic detected: HTTP traffic on port 50121 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49996
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49995
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49994
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49993
Source: unknown Network traffic detected: HTTP traffic on port 50016 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49992
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49991
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49990
Source: unknown Network traffic detected: HTTP traffic on port 49786 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49874 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49829 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49934 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50199 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49989
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49988
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49987
Source: unknown Network traffic detected: HTTP traffic on port 50151 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50116 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50225 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49803 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50071 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49849 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49900 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50106
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50108
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50107
Source: unknown Network traffic detected: HTTP traffic on port 49837 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50109
Source: unknown Network traffic detected: HTTP traffic on port 49929 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50100
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50102
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50101
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50104
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50103
Source: unknown Network traffic detected: HTTP traffic on port 49964 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50128 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50197 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50117
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50116
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50119
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50118
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50111
Source: unknown Network traffic detected: HTTP traffic on port 49930 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50110
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50113
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50112
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50115
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50114
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49986 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49850 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50175 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50213 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50128
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798
Source: unknown Network traffic detected: HTTP traffic on port 50012 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50127
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49797
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49796
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50129
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49795
Source: unknown Network traffic detected: HTTP traffic on port 49952 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50120
Source: unknown Network traffic detected: HTTP traffic on port 50093 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50122
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50121
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50124
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50123
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50126
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50125
Source: unknown Network traffic detected: HTTP traffic on port 50048 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49825 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49884 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49907 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49789
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49894 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50106 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49942 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50081 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50173 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49919 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49954 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50014 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49988 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50201 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49827 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50046 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49882 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50141 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50233 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49976 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50118 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49815 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50223 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50024 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50163 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49998 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50058 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50002 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50185 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49920 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49926 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50054
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50053
Source: unknown Network traffic detected: HTTP traffic on port 49789 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50056
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50055
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50058
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50057
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50059
Source: unknown Network traffic detected: HTTP traffic on port 49961 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50061
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50060
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50063
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50062
Source: unknown Network traffic detected: HTTP traffic on port 50102 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50045 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50148 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50064
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50067
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50066
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50069
Source: unknown Network traffic detected: HTTP traffic on port 50205 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50183 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50070
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50072
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50071
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50074
Source: unknown Network traffic detected: HTTP traffic on port 49823 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50073
Source: unknown Network traffic detected: HTTP traffic on port 50080 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49869 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50227 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50195 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50076
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50075
Source: unknown Network traffic detected: HTTP traffic on port 50057 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50078
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50077
Source: unknown Network traffic detected: HTTP traffic on port 50114 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49892 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50079
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50081
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50080
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50083
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50082
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50085
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50084
Source: unknown Network traffic detected: HTTP traffic on port 49904 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49847 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50087
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50086
Source: unknown Network traffic detected: HTTP traffic on port 49870 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50089
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50088
Source: unknown Network traffic detected: HTTP traffic on port 50079 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50090
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50092
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50091
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50094
Source: unknown Network traffic detected: HTTP traffic on port 50136 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49983 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50093
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50096
Source: unknown Network traffic detected: HTTP traffic on port 49938 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50095
Source: unknown Network traffic detected: HTTP traffic on port 49811 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50018
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50017
Source: unknown Network traffic detected: HTTP traffic on port 50193 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50019
Source: unknown Network traffic detected: HTTP traffic on port 49813 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49951 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50010
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50012
Source: unknown Network traffic detected: HTTP traffic on port 49916 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50055 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50011
Source: unknown Network traffic detected: HTTP traffic on port 50090 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50014
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50013
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50016
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50015
Source: unknown Network traffic detected: HTTP traffic on port 50161 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49845 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50215 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50230 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50029
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50020
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50022
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50024
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50027
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49879 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49985 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50030
Source: unknown Network traffic detected: HTTP traffic on port 50067 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50039
Source: unknown Network traffic detected: HTTP traffic on port 49995 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50011 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50032
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50031
Source: unknown Network traffic detected: HTTP traffic on port 49857 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50034
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50033
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50035
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50038
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50037
Source: unknown Network traffic detected: HTTP traffic on port 49801 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50041
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50040
Source: unknown Network traffic detected: HTTP traffic on port 50104 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50089 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49973 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50203 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50033 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50171 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50043
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50042
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50045
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50044
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50047
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50046
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50049
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50048
Source: unknown Network traffic detected: HTTP traffic on port 49880 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50050
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50052
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50051
Source: unknown Network traffic detected: HTTP traffic on port 50126 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50168 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50122 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49912 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49958 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50219 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49946 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50018 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50077 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50134 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49855 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50053 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49981 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49924 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50099 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49831 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50031 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50156 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50043 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50100 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50207 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49808 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50006 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50181 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49867 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49865 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49942
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49941
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49940
Source: unknown Network traffic detected: HTTP traffic on port 50229 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50098
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50097
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50099
Source: unknown Network traffic detected: HTTP traffic on port 50112 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50075 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50158 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49939
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49938
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49937
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49936
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49935
Source: unknown Network traffic detected: HTTP traffic on port 49902 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49934
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49933
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49932
Source: unknown Network traffic detected: HTTP traffic on port 50087 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49931
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49930
Source: unknown Network traffic detected: HTTP traffic on port 50008 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49971 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49936 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49929
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49928
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49927
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49926
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49925
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49924
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49923
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49922
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49921
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49920
Source: unknown Network traffic detected: HTTP traffic on port 50063 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50124 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50191 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49821 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49877 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50217 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49914 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49919
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49918
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49917
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49916
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49915
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49914
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49913
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49912
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49910
Source: unknown Network traffic detected: HTTP traffic on port 49948 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50041 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49843 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50146 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50097 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49909
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49908
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49907
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49906
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49905
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49904
Source: unknown HTTPS traffic detected: 34.197.163.13:443 -> 192.168.2.16:49728 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.231.17.194:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.231.17.194:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.21.223.151:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknown HTTPS traffic detected: 18.208.47.8:443 -> 192.168.2.16:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 107.22.173.72:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.197.163.13:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 44.205.78.241:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.211.23.45:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.73.100.250:443 -> 192.168.2.16:50127 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.235.239.81:443 -> 192.168.2.16:50175 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.235.239.81:443 -> 192.168.2.16:50184 version: TLS 1.2
Source: unknown HTTPS traffic detected: 18.154.132.81:443 -> 192.168.2.16:50198 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.235.76.136:443 -> 192.168.2.16:50200 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.3.124.253:443 -> 192.168.2.16:50201 version: TLS 1.2

Key, Mouse, Clipboard, Microphone and Screen Capturing

barindex
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Windows user hook set: Path: unknown Event Start:focus Event End: focus Module: NULL
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Windows user hook set: Path: unknown Event Start:focus Event End: focus Module: NULL
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: sus27.winEXE@76/502@39/251
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Mutant created: \Sessions\1\BaseNamedObjects\com.grammarly.ProjectLlama.SingleInstance
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Mutant created: NULL
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Mutant created: \Sessions\1\BaseNamedObjects\grammarly.desktop.installer-6e9b97a3-dfe7-4a91-afbe-8e51f7be6d6c
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Temp\nsm152A.tmp
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File read: C:\Users\desktop.ini
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe File read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File read: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
Source: unknown Process created: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe "C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe"
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe "C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe" new-version-v2 onboarding
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /NH /FI "IMAGENAME eq Grammarly.Desktop.exe"
Source: C:\Windows\SysWOW64\tasklist.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --enable-features=MojoIpcz --mojo-named-platform-channel-pipe=7104.3668.17407409699958160167
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-GB --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_CH" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:1
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=2028,i,1723528232903650596,3920355234927745539,262144 /prefetch:3
Source: C:\Windows\explorer.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2612 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:3
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=6qrxDAzOWbV4ISaXbaeblzbqt1-zHDJKTAsNkxFACRE&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe "C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe" new-version-v2 onboarding
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /NH /FI "IMAGENAME eq Grammarly.Desktop.exe"
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=7364 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=7468 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=6qrxDAzOWbV4ISaXbaeblzbqt1-zHDJKTAsNkxFACRE&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: unknown unknown
Source: C:\Windows\explorer.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-GB --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_CH" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:1
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=YMT3ROP5autsdjZ_tsNOQAOfNJfh5L4UPzMB0_suXcA&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6796 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=DedXj_1j5KNl-qml7Yln6Y4k7TpJCcoTkY4W331meKk&verify=j4bHc&showSuccessState=true
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2612 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:3
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=7364 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=7468 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6796 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: propsys.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: cryptbase.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: oleacc.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: shfolder.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: riched20.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: usp10.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: msls31.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: mswsock.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: dnsapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: rasadhlp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: fwpuclnt.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: cryptsp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: rsaenh.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: profapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: linkinfo.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: ntshrui.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: sspicli.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: srvcli.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: cscapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: edputil.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: urlmon.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: iertutil.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: netutils.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: appresolver.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: bcp47langs.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: slc.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: sppc.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: mscoree.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: cryptsp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: rsaenh.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: windows.applicationmodel.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: twinapi.appcore.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: propsys.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: msasn1.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: riched20.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: usp10.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: msls31.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: gpapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dnsapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dhcpcsvc6.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dhcpcsvc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: winnsi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: rasapi32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: rasman.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: rtutils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: rasadhlp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: fwpuclnt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: secur32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: schannel.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: mskeyprotect.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: ncryptsslp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: windows.ui.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: windowmanagementapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: inputhost.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dwrite.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: msvcp140_clr0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: uiautomationcore.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: netfxperf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: pdh.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: wtsapi32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: bitsperf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: bitsproxy.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: esentprf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: perfts.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: winsta.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: utildll.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: tdh.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: msdtcuiu.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: atl.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: msdtcprx.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: mtxclu.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: clusapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: resutils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: ktmw32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: wkscli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: cscapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: msscntrs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: perfdisk.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: wmiclnt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: perfnet.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: browcli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: perfos.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: perfproc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: sysmain.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: umpdc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: powrprof.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: rasctrs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: tapiperf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: perfctrs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: usbperf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: wbemcomn.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: tquery.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: cryptdll.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: appresolver.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: bcp47langs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: slc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: sppc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: windowscodecs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: linkinfo.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: thumbcache.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dpapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: policymanager.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: msvcp110_win.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: perfproc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: d3d9.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: d3d10warp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: oleacc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: uiamanager.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: wtsapi32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: winsta.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: powrprof.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: umpdc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dataexchange.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: d3d11.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dcomp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dxgi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: resourcepolicyclient.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dxcore.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: msctfui.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: d3dcompiler_47.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: dbghelp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: actxprxy.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: twinapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: ia2comproxy.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: version.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: windows.system.profile.platformdiagnosticsandusagedatasettings.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: policymanager.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: kbdus.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: windows.system.profile.platformdiagnosticsandusagedatasettings.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: policymanager.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: wkscli.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: netutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: mdmregistration.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: mdmregistration.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: omadmapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: powrprof.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dmcmnutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: iri.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: umpdc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dsreg.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: powrprof.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: umpdc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dwrite.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dpapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: nlaapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dnsapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: windows.ui.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: windowmanagementapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: inputhost.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: twinapi.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: twinapi.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: propsys.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: wtsapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: mscms.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: coloradapterclient.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: winsta.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: windows.security.authentication.web.core.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: iertutil.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: devobj.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dataexchange.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: d3d11.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dcomp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dxgi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: resourcepolicyclient.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: mf.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: mfplat.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: rtworkq.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: hevcdecoder.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dolbydecmft.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: mfperfhelper.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dwmapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: uiautomationcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: atlthunk.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: oleacc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: directmanipulation.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: d3d11.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: d3d10warp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dbghelp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dxcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dcomp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: dwrite.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: windows.security.authentication.onlineid.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: policymanager.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Section loaded: msvcp110_win.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Section loaded: windows.shell.servicehostbuilder.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /NH /FI "IMAGENAME eq Grammarly.Desktop.exe"
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Grammarly Desktop Integrations
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Static PE information: certificate valid
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Static file information: File size 18314104 > 1048576
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm64\native\WebView2Loader.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\NScurl.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.CheetahClient.Protocol.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.IAccessible2Lib.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\WebView2Loader.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\WebView2Loader.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\nsExec.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.UI.Onboarding.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm\native\e_sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.StorageClient.Protocol.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Serialization.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LZStringCSharp.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\e_sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\e_sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Uninstall.exe Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.UIAutomation.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-DiffMatchPatch.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NHotkey.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NLog.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NewtonsoftJson.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-Validation.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-dotnet.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Grammarly
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Grammarly
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Memory allocated: 27D3A450000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Memory allocated: 27D52550000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Window / User API: threadDelayed 8585
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Window / User API: threadDelayed 1242
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm64\native\WebView2Loader.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\NScurl.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.CheetahClient.Protocol.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.IAccessible2Lib.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\WebView2Loader.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\WebView2Loader.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\nsExec.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.UI.Onboarding.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm\native\e_sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.StorageClient.Protocol.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Serialization.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LZStringCSharp.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\e_sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\e_sqlite3.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Uninstall.exe Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.UIAutomation.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dll Jump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe TID: 5504 Thread sleep time: -7378697629483816s >= -30000s
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe TID: 4872 Thread sleep count: 8585 > 30
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe TID: 4872 Thread sleep count: 1242 > 30
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\d0010809
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe File Volume queried: C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Code Cache\js FullSizeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe File Volume queried: C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Code Cache\wasm FullSizeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData\Local
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe File opened: C:\Users\user\AppData\Local\Grammarly
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process information queried: ProcessInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process token adjusted: Debug
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Memory allocated: page read and write | page guard
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe "C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe" new-version-v2 onboarding
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /NH /FI "IMAGENAME eq Grammarly.Desktop.exe"
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=6qrxDAzOWbV4ISaXbaeblzbqt1-zHDJKTAsNkxFACRE&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-GB --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_CH" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:1
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: unknown unknown
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --enable-features=mojoipcz --mojo-named-platform-channel-pipe=7104.3668.17407409699958160167
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview\crashpad --annotation=isofficialbuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=win64 "--annotation=prod=edge webview2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=waaaaaaaaadgaaamaaaaaaaaaaaaaaaaaabgaaaaaaa4aaaaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaagaaaaaaaaaayaaaaaaaaaagaaaaaaaaacaaaaaaaaaaiaaaaaaaaaa== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.networkservice --lang=en-gb --service-sandbox-type=none --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.storageservice --lang=en-gb --service-sandbox-type=service --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-gb --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_ch" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:1
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview\crashpad --annotation=isofficialbuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=win64 "--annotation=prod=edge webview2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=waaaaaaaaadgaaamaaaaaaaaaaaaaaaaaabgaaaaaaa4aaaaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaagaaaaaaaaaayaaaaaaaaaagaaaaaaaaacaaaaaaaaaaiaaaaaaaaaa== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.networkservice --lang=en-gb --service-sandbox-type=none --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.storageservice --lang=en-gb --service-sandbox-type=service --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Process created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-gb --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_ch" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:1
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\netstandard\v4.0_2.0.0.0__cc7b13ffcd2ddd51\netstandard.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\System32\WinMetadata\Windows.UI.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\System32\WinMetadata\Windows.Foundation.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.WindowsRuntime\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.WindowsRuntime.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.InteropServices.WindowsRuntime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.InteropServices.WindowsRuntime.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Collections.Immutable.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NLog.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Bcl.AsyncInterfaces.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Newtonsoft.Json.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Interfaces.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Linq.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Json.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.User32.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.ValueTuple.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Threading.Tasks.Extensions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\websocket-sharp.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\System32\WinMetadata\Windows.Services.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\System32\WinMetadata\Windows.UI.Xaml.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Wpf.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Kernel32.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Toolkit.Uwp.Notifications.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\System32\WinMetadata\Windows.Storage.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.ShellSuserngApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Resources.Extensions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Memory.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Runtime.CompilerServices.Unsafe.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Numerics.Vectors.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userbrii.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userbrili.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userbrib.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userFR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userFI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userFB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userST.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userSTI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userSTB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\userSTBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\flat_officeFontsPreview.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\OFFSYM.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\OFFSYMSL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\OFFSYMSB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\OFFSYMXL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\OFFSYML.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\OFFSYMB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\WordApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NetOffice.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Xaml.Behaviors.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\Trust Protection Lists\manifest.json VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\WidevineCdm\manifest.json VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe Queries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs