Source: Taskmgr.exe, 0000000E.00000003.1472545843.000001C7EFB84000.00000004.00000020.00020000.00000000.sdmp, Taskmgr.exe, 0000000E.00000003.1473390487.000001C7EFBA9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://go.m |
Source: Taskmgr.exe, 0000000E.00000003.1472545843.000001C7EFB84000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://go.microsPk |
Source: Taskmgr.exe, 0000000E.00000003.1472545843.000001C7EFB84000.00000004.00000020.00020000.00000000.sdmp, Taskmgr.exe, 0000000E.00000003.1473390487.000001C7EFBA9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://go.microsoft.c |
Source: Taskmgr.exe, 0000000E.00000003.1472545843.000001C7EFB84000.00000004.00000020.00020000.00000000.sdmp, Taskmgr.exe, 0000000E.00000003.1473390487.000001C7EFBA9000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://go.microsoft.co |
Source: MicrosoftEdgeUpdate.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: MicrosoftEdgeUpdate.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: MicrosoftEdgeUpdate.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: MicrosoftEdgeUpdate.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: MicrosoftEdgeUpdate.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: MicrosoftEdgeUpdate.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Hypervisor Root Partition/ |
Source: Taskmgr.exe, 0000000E.00000003.1475341722.000001C7EFB9B000.00000004.00000020.00020000.00000000.sdmp, Taskmgr.exe, 0000000E.00000003.1472545843.000001C7EFB84000.00000004.00000020.00020000.00000000.sdmp, Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFB9D000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V VM Vid Partitionll |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp, Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Dynamic Memory Integration Service |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Hypervisor Root Virtual Processor |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: 2Hyper-V Heartbeat Service |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: HHyper-V Volume Shadow Copy Requestor& |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F0188000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&0000000 |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: THyper-V Hypervisor Root Virtual Processor |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: JHyper-V Hypervisor Logical Processor8 |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: THyper-V Hypervisor Root Virtual Processor |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: >Hyper-V Guest Service Interface |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: sWDHyper-V Hypervisor Root Partition |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: DHyper-V Hypervisor Root Partition |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: &Hyper-V Hypervisor |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: :Hyper-V Data Exchange Service |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: DHyper-V Virtual Machine Bus Pipes |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Dynamic Memory Integration Service* |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: BHyper-V PowerShell Direct Service |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: X2Hyper-V VM Vid Partition$'-" |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \\?\SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Hypervisor Logical Processor.syszU |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F0170000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V nyyempmfbiidaux Bus3 |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: VHyper-V Dynamic Memory Integration Service$ |
Source: Taskmgr.exe, 0000000E.00000003.1475341722.000001C7EFB9B000.00000004.00000020.00020000.00000000.sdmp, Taskmgr.exe, 0000000E.00000003.1472545843.000001C7EFB84000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V VM Vid Partitionz_ |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Hypervisor Root Virtual ProcessorF |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Hypervisor Root Partition |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Hypervisor, |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: vmicshutdownSubSyst |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: 2Hyper-V VM Vid Partitionx |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: VHyper-V Dynamic Memory Integration Service|x |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: JHyper-V Hypervisor Logical ProcessorO |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Hypervisor Logical Processor.mui| |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Virtual Machine Bus Pipes |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Virtual Machine Bus Pipesl |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: AlDHyper-V Virtual Machine Bus Pipes% |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: ZHyper-V Remote Desktop Virtualization Service |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: vmicvss |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: VMware Virtual disk SCSI Disk Device |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EFAA7000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V nyyempmfbiidaux Bus Pipes |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000^ |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V Hypervisor |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: <Hyper-V Guest Shutdown Service@ |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: &Hyper-V HypervisorXG |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F0188000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: VMware Virtual disk SCSI Disk DeviceZ |
Source: Taskmgr.exe, 0000000E.00000002.2381381348.000001C7F021F000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: HHyper-V Time Synchronization Service& |
Source: Taskmgr.exe, 0000000E.00000002.2377809703.000001C7EF980000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: vmicheartbeat |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\ProgramData\Microsoft\User Account Pictures\user.png VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Assets\SmallLogo.scale-100.png VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\Assets\Icons\AppListIcon.scale-100.png VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_neutral_split.scale-100_8wekyb3d8bbwe\Assets\AppTiles\StoreAppList.scale-100.png VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Windows\System32\RuntimeBroker.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Windows\System32\RuntimeBroker.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\Assets\Icons\AppListIcon.scale-100.png VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Assets\SmallLogo.scale-100.png VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Assets\SquareLogo44x44.scale-100.png VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Program Files\WindowsApps\Microsoft.WindowsAlarms_10.1906.2182.0_x64__8wekyb3d8bbwe\Assets\AlarmsAppList.targetsize-256.png VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\Taskmgr.exe |
Queries volume information: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Assets\SquareLogo44x44.scale-100.png VolumeInformation |
Jump to behavior |