Source: unknown | Process created: C:\Windows\System32\OpenWith.exe C:\Windows\system32\OpenWith.exe -Embedding |
Source: C:\Windows\System32\OpenWith.exe | Process created: C:\Program Files\7-Zip\7zFM.exe "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\user\Desktop\#U6696#U901a.rar" |
Source: C:\Program Files\7-Zip\7zFM.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\7zO43792B4F\??.pdf" |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=5416 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7056 |
Source: C:\Windows\System32\OpenWith.exe | Process created: C:\Program Files\7-Zip\7zFM.exe "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\user\Desktop\#U6696#U901a.rar" |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=6152 |
Source: C:\Program Files\7-Zip\7zFM.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\7zO43792B4F\??.pdf" |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=3960 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=5416 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=2120 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=2628 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" GetChannelUri |
Source: C:\Program Files\7-Zip\7zFM.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\7zO437BF08F\??-2.pdf" |
Source: C:\Program Files\7-Zip\7zFM.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\7zO437BF08F\??-2.pdf" |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe" GetChannelUri |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2284 --field-trial-handle=1612,i,11901564035657534288,5559827856949093170,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=7056 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=6152 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=3960 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=2120 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -c --type=collab-renderer --proc=2628 |
Source: C:\Program Files\7-Zip\7zFM.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\7zO4376D6CF\??-8.pdf" |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2164 --field-trial-handle=1216,i,17584164008921770117,15795344887374319695,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 |
Source: C:\Program Files\7-Zip\7zFM.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\7zO4377A720\??-7.pdf" |
Source: C:\Program Files\7-Zip\7zFM.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\7zO4376D6CF\??-8.pdf" |
Source: C:\Program Files\7-Zip\7zFM.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\7zO4377A720\??-7.pdf" |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2112 --field-trial-handle=1644,i,9793751150463550172,10423207747549681099,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2284 --field-trial-handle=1612,i,11901564035657534288,5559827856949093170,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2164 --field-trial-handle=1216,i,17584164008921770117,15795344887374319695,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2112 --field-trial-handle=1644,i,9793751150463550172,10423207747549681099,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process created: unknown unknown |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: uxtheme.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: onecoreuapcommonproxystub.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.storage.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: wldp.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: twinui.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: wintypes.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: powrprof.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dwmapi.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: pdh.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: umpdc.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: onecorecommonproxystub.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: actxprxy.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: propsys.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.staterepositoryps.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.ui.appdefaults.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.ui.immersive.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: profapi.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: ntmarta.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: uiautomationcore.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dui70.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: duser.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dwrite.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: bcp47mrm.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: uianimation.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: d3d11.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dxgi.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: d3d10warp.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: resourcepolicyclient.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dxcore.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dcomp.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: oleacc.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: edputil.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.ui.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windowmanagementapi.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: textinputframework.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: inputhost.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coremessaging.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coreuicomponents.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coreuicomponents.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: twinapi.appcore.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coremessaging.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coremessaging.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: twinapi.appcore.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: coremessaging.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windowscodecs.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: thumbcache.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: policymanager.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: msvcp110_win.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: apphelp.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: appresolver.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: bcp47langs.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: slc.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: userenv.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: sppc.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: tiledatarepository.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: staterepository.core.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.staterepository.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: wtsapi32.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.staterepositorycore.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: mrmcorer.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: appxdeploymentclient.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: sxs.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: directmanipulation.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: textshaping.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: ninput.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: explorerframe.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: dataexchange.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.ui.fileexplorer.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: xmllite.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: structuredquery.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: atlthunk.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.fileexplorer.common.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: iertutil.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: windows.storage.search.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: linkinfo.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: twinapi.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: ntshrui.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: sspicli.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: srvcli.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: cscapi.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: winmm.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: networkexplorer.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: ehstorshell.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: cscui.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: urlmon.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: netutils.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: pcacli.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: mpr.dll |
Source: C:\Windows\System32\OpenWith.exe | Section loaded: sfc_os.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: uxtheme.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: kernel.appcore.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: textshaping.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: windows.storage.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: wldp.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: windowscodecs.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: profapi.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: propsys.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: explorerframe.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: cryptbase.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: thumbcache.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: policymanager.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: msvcp110_win.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: textinputframework.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: coreuicomponents.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: coremessaging.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: ntmarta.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: wintypes.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: wintypes.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: wintypes.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: dataexchange.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: d3d11.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: dcomp.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: dxgi.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: twinapi.appcore.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: edputil.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: urlmon.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: iertutil.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: srvcli.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: netutils.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: windows.staterepositoryps.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: sspicli.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: appresolver.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: bcp47langs.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: slc.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: userenv.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: sppc.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: onecorecommonproxystub.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: onecoreuapcommonproxystub.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: pcacli.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: mpr.dll |
Source: C:\Program Files\7-Zip\7zFM.exe | Section loaded: sfc_os.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: apphelp.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: vccorlib140.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: msvcp140.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: vcruntime140.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: kernel.appcore.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: appcontracts.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: wintypes.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: cdprt.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: cdp.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: windows.storage.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: wldp.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: umpdc.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: propsys.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: dsreg.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: msvcp110_win.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: cryptsp.dll |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\FullTrustNotifier.exe | Section loaded: onecoreuapcommonproxystub.dll |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\OpenWith.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\7-Zip\7zFM.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | Process information set: NOOPENFILEERRORBOX |