Windows Analysis Report
camphoto_1144747756.mp4

Overview

General Information

Sample name: camphoto_1144747756.mp4
(renamed file extension from heic to mp4)
Original sample name: camphoto_1144747756.heic
Analysis ID: 1432153
MD5: 53adfb8e1b3128a99cccd508fb1832a6
SHA1: c0b886b84e36c8e792d11283aa91cdce839077e4
SHA256: 0ea08cb0f8c2133f948a5633e30440ebe01039cf685f2a4d5aad9b33599c0f20
Infos:

Detection

Score: 6
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Signatures

Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Checks for available system drives (often done to infect USB drives)
Creates a process in suspended mode (likely to inject code)
Creates a window with clipboard capturing capabilities
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file does not import any functions
Queries the volume information (name, serial number etc) of a device
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Stores large binary data to the registry

Classification

Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: z: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: x: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: v: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: t: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: r: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: p: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: n: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: l: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: j: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: h: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: f: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: b: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: y: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: w: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: u: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: s: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: q: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: o: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: m: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: k: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: i: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: g: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: e: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: c: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: a: Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Directory queried: number of queries: 1001
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries Jump to behavior
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: www.login.yahoo.com0 equals www.yahoo.com (Yahoo)
Source: msdt.exe, 00000007.00000002.613700952.0000000002660000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp, msdt.exe, 00000007.00000002.613700952.0000000002660000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/UTN-USERFirst-Hardware.crl06
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/2048ca.crl0
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/server1.crl0
Source: msdt.exe, 00000007.00000002.613700952.0000000002660000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
Source: msdt.exe, 00000007.00000002.613272010.000000000024A000.00000004.00000020.00020000.00000000.sdmp, msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp, msdt.exe, 00000007.00000002.613700952.0000000002660000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0%
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0-
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0/
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com05
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net03
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net0D
Source: wmplayer.exe, 00000000.00000002.614694076.0000000006010000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://pro.corbis.com/search/searchresults.asp?txt=42-15564978&openImage=42-15564978:li
Source: wmplayer.exe, 00000000.00000002.614694076.0000000006010000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://pro.corbis.com/search/searchresults.asp?txt=42-17066732&openImage=42-17066732XRe
Source: wmplayer.exe, 00000000.00000002.613861620.0000000003D46000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://pro.corbis.com/search/searchresults.asp?txt=42-17167222&openImage=42-171672228BIM
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com.my/cps.htm02
Source: msdt.exe, 00000007.00000002.613272010.000000000024A000.00000004.00000020.00020000.00000000.sdmp, msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0
Source: msdt.exe, 00000007.00000002.613272010.0000000000277000.00000004.00000020.00020000.00000000.sdmp, msdt.exe, 00000007.00000002.613700952.0000000002660000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://secure.comodo.com/CPS0
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Window created: window name: CLIPBRDWNDCLASS Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: DiagPackage.dll.mui.7.dr Static PE information: No import functions for PE file found
Source: DiagPackage.dll.7.dr Static PE information: No import functions for PE file found
Source: DiagPackage.dll.mui.7.dr Static PE information: Section .rsrc
Source: DiagPackage.dll.7.dr Static PE information: Section .rsrc
Source: classification engine Classification label: clean6.winMP4@15/29@0/0
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File created: C:\Users\user\AppData\Local\Microsoft\Media Player\Transcoded Files Cache Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\Microsoft_WMP_70_CheckForOtherInstanceMutex
Source: C:\Windows\SysWOW64\msdt.exe File created: C:\Users\user\AppData\Local\Temp\msdtadmin Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: unknown Process created: C:\Program Files (x86)\Windows Media Player\wmplayer.exe "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:6 /Open "C:\Users\user\Desktop\camphoto_1144747756.mp4"
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wow64win.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wow64cpu.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: mfplat.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: avrt.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: audioses.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: rpcrtremote.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wevtapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: samlib.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: slc.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: mf.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: atl.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ksuser.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: msdmo.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: duser.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dui70.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dxva2.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: d3d9.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: d3d8thk.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: rgb9rast.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmerror.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: pcwum.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: shsvcs.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: rapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: xmllite.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: davhlpr.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: webio.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Section loaded: bcrypt.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe Automated click: Next
Source: C:\Windows\SysWOW64\msdt.exe File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\SysWOW64\msdt.exe File created: C:\Windows\Temp\SDIAG_57d12060-20b6-45ab-a73b-de5201e22bf7\en-US\DiagPackage.dll.mui Jump to dropped file
Source: C:\Windows\SysWOW64\msdt.exe File created: C:\Windows\Temp\SDIAG_57d12060-20b6-45ab-a73b-de5201e22bf7\DiagPackage.dll Jump to dropped file
Source: C:\Windows\SysWOW64\msdt.exe File created: C:\Windows\Temp\SDIAG_57d12060-20b6-45ab-a73b-de5201e22bf7\en-US\DiagPackage.dll.mui Jump to dropped file
Source: C:\Windows\SysWOW64\msdt.exe File created: C:\Windows\Temp\SDIAG_57d12060-20b6-45ab-a73b-de5201e22bf7\DiagPackage.dll Jump to dropped file
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Key value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Multimedia\ActiveMovie\Filter Cache 0 Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Window / User API: threadDelayed 1010 Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Window / User API: threadDelayed 558 Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Dropped PE file which has not been started: C:\Windows\Temp\SDIAG_57d12060-20b6-45ab-a73b-de5201e22bf7\en-US\DiagPackage.dll.mui Jump to dropped file
Source: C:\Windows\SysWOW64\msdt.exe Dropped PE file which has not been started: C:\Windows\Temp\SDIAG_57d12060-20b6-45ab-a73b-de5201e22bf7\DiagPackage.dll Jump to dropped file
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe TID: 1904 Thread sleep time: -120000s >= -30000s Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Memory protected: page readonly | page guard Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Process created: C:\Windows\SysWOW64\msdt.exe "C:\Windows\System32\msdt.exe" -id WindowsMediaPlayerLibraryDiagnostic Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Program Files (x86)\Windows Media Player\wmplayer.exe VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Program Files (x86)\Windows Media Player\wmplayer.exe VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Program Files (x86)\Windows Media Player\wmplayer.exe VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\Public\Music\Sample Music\Kalimba.mp3 VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\Public\Music\Sample Music\Sleep Away.mp3 VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\Users\Public\Videos\Sample Videos\Wildlife.wmv VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Queries volume information: C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-WindowsMediaPlayer-Troubleshooters-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Directory queried: number of queries: 1001
No contacted IP infos